CVE-2024-28389

Publication date

2024-03-19 00:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.