What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Web-X Be POPIA Compliant be-popia-compliant allows SQL Injection.This issue affects Be POPIA Compliant: from n/a through 1.2.0.
Explanation of Vulnerability in Simple Terms
02Summary
Be POPIA Compliant versions up to 1.2.0 contain a SQL injection vulnerability accessible over the network. An attacker can craft a malicious request that, when a user visits a link or page, executes arbitrary SQL queries against the site's database. This can expose sensitive data or degrade site performance. Update to a version newer than 1.2.0.
What an attacker can do
03Attacker Capabilities
Execute SQL queries to read or modify database contents if a user visits a malicious link.
Potential impact on your site
04Site Impact
Database contents may be exposed or corrupted; site availability may be affected.
Conditions required to exploit
05Prerequisites
Network access and user interaction required; no authentication needed.
Key dates
06Disclosure timeline
November 3, 2023
CVE published
April 28, 2026
Record updated