Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-25319 1 Wende60 1 Redaxo Cms Addon Myevents 2026-05-17 7.1 High
Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Attackers can send GET requests to the event_add.php page with malicious myevents_id values to extract or modify sensitive database information.