Vulnerabilities > Xoops > Xoops > 2.5.7.2

DATE CVE VULNERABILITY TITLE RISK
2017-03-30 CVE-2017-7290 SQL Injection vulnerability in Xoops 2.5.7.2/2.5.7.3/2.5.8.1
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php.
network
low complexity
xoops CWE-89
6.5