Vulnerabilities > K IWI

DATE CVE VULNERABILITY TITLE RISK
2018-11-16 CVE-2018-18755 SQL Injection vulnerability in K-Iwi 1775
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.
network
low complexity
k-iwi CWE-89
critical
9.8