What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.
Explanation of Vulnerability in Simple Terms
02Summary
The Accessibility Suite by Online ADA versions up to 4.12 contain a SQL injection vulnerability in a database query that processes user input without proper sanitization. An attacker with low-level privileges can craft malicious input to read sensitive data from the database, modify records, or degrade site performance. The vulnerability requires network access and specific conditions to exploit.
What an attacker can do
03Attacker Capabilities
Read sensitive database records, modify data, or degrade site performance via SQL injection.
Potential impact on your site
04Site Impact
Unauthorized access to database contents, data modification, or denial of service affecting site functionality.
Conditions required to exploit
05Prerequisites
Attacker must have low-level user account access; no user interaction required.
Key dates
06Disclosure timeline
November 6, 2023
CVE published
April 28, 2026
Record updated