A vulnerability was found in code-projects Fantasy...
Moderate severity
Unreviewed
Published
Jan 19, 2025
to the GitHub Advisory Database
•
Updated Jan 19, 2025
Description
Published by the National Vulnerability Database
Jan 19, 2025
Published to the GitHub Advisory Database
Jan 19, 2025
Last updated
Jan 19, 2025
A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been classified as critical. Affected is an unknown function of the file /dash/update.php. The manipulation of the argument uname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References