2019-05-22 15:47:20
mitre
PUBLISHED
CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2.