JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
Software | From | Fixed in |
---|---|---|
gwesystems / jevents | - | 3.4.0 |
gwesystems / jevents | 3.4.0 | 3.4.0.x |
gwesystems / jevents | 3.4.0-rc | 3.4.0-rc.x |
gwesystems / jevents | 3.4.0-rc3 | 3.4.0-rc3.x |
gwesystems / jevents | 3.4.0-rc4 | 3.4.0-rc4.x |
gwesystems / jevents | 3.4.0-rc5 | 3.4.0-rc5.x |