What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3.
Explanation of Vulnerability in Simple Terms
RSVPMaker versions up to 9.9.3 contain a SQL injection vulnerability in database queries. An attacker with high-level privileges can inject malicious SQL code to read sensitive data, modify records, or disrupt the database. The vulnerability requires administrative or elevated access to exploit.
What an attacker can do
Read, modify, or delete database records; extract sensitive information from the database.
Potential impact on your site
If a compromised admin account exists, the attacker can access or alter event data, registrations, and other stored information.
Conditions required to exploit
Attacker must have high-level privileges (admin or equivalent access) on the site.
Key dates
External resources
Related vulnerabilities