b2evolution Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2021-28242
SQL Injection in the quotevoadm.phpquot component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the quotcf_namequot parameter when creating a new filter under the quotCollectionsquot tab.