1 results (0.002 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

ai-dev aicombinationsonfly before v0.3.1 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. • https://security.friendsofpresta.org/modules/2023/06/28/aicombinationsonfly.html https://www.boutique.ai-dev.fr/en/ergonomie/61-combinations-on-fly.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •