CubeCart Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2018-20716 - Vulnerability Database

CubeCart Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2018-20716

Critical
Reference: CVE-2018-20716
Title: CubeCart Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

CubeCart before 6.1.13 has SQL Injection via the validate parameter of the quotI forgot my Passwordquot feature.