A vulnerability has been reported for nPHP that may result in a remote attacker obtaining elevated privileges. The vulnerability exists due to insufficient sanitization of user-supplied input. Specifically, the 'e-mail' field is not sanitized of '<~>' characters. These characters are used by newsPHP to delimit fields in the database.
A vulnerability has been reported for nPHP that may result in a remote attacker obtaining elevated privileges. The vulnerability exists due to insufficient sanitization of user-supplied input. Specifically, the 'e-mail' field is not sanitized of '<~>' characters. These characters are used by newsPHP to delimit fields in the database.