CVE-2024-28389 Information
Mar 20, 2024
cve
Description
SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.
Reference
https://security.friendsofpresta.org/modules/2024/03/12/spinwheel.html
Share on: