Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
| Software | From | Fixed in |
|---|---|---|
| candypress / candypress_store | 3.5.2.14 | 3.5.2.14.x |