A vulnerability has been discovered in PostNuke Phoenix v0.723 and earlier. Specifically, the Members_List module fails to sufficiently sanitize user-supplied input, making it prone to SQL injection attacks. Exploitation may allow for modification of SQL queries, resulting in information disclosure, or database corruption. It has been discovered that PostNuke Phoenix v0.723 and earlier are prone to SQL injection attacks.
A vulnerability has been discovered in PostNuke Phoenix v0.723 and earlier. Specifically, the Members_List module fails to sufficiently sanitize user-supplied input, making it prone to SQL injection attacks. Exploitation may allow for modification of SQL queries, resulting in information disclosure, or database corruption. It has been discovered that PostNuke Phoenix v0.723 and earlier are prone to SQL injection attacks.