SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18716
Reference (s):
- https://www.seebug.org/vuldb/ssvid-97867

