Macrob7 Macs Framework Content Management System – 1.14f was discovered to contain a SQL injection vulnerability via the ‘roleId’ parameter of the `editRole` and `deletUser` modules.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23045
Reference (s):
- https://www.vulnerability-lab.com/get_content.php?id=2206

