webSPELL version 4.2.4 suffers from cross site request forgery and remote SQL injection vulnerabilities.