Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26677
Reference (s):
- http://vfairs.com
- https://api.vfairs.com/v1/users/
- https://www.huntress.com/blog/zero-day-vulnerabilities-in-popular-event-management-platforms-could-leave-msps-open-to-attack

