doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when actionsiteweb. A remote background administrator privilege user (or a user with permission to manage configuration siteweb) could exploit the vulnerability to obtain database sensitive information.
Publication date: Wed, 01 May 2019 01:29:00 +0000