Security Advisory
CVE-2020-26677
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.