What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log user-activity-log allows SQL Injection.This issue affects User Activity Log: from n/a through 1.6.2.
Explanation of Vulnerability in Simple Terms
02Summary
User Activity Log versions up to 1.6.2 contain a SQL injection vulnerability in a high-privilege function. An authenticated administrator can inject malicious SQL through unfiltered input, potentially reading sensitive database records. The vulnerability affects the scope beyond the vulnerable component. No user interaction is required once an admin account is compromised or misused.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site's database by injecting SQL commands through the vulnerable function.
Potential impact on your site
04Site Impact
A compromised or malicious admin account can extract sensitive database information without additional user interaction.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative privileges on the site.
Key dates
06Disclosure timeline
October 31, 2023
CVE published
April 29, 2026
Record updated