"Zinho" <email@example.com> is credited with the discovery of this issue.
MaxWebPortal MaxWebPortal 1.33
Multiple input validation vulnerabilities affect MaxWebPortal. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating dynamic Web content.
An attacker may exploit this issue to manipulate SQL queries to the underlying database and have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate theft of sensitive information, potentially including authentication credentials, and data corruption.
No exploit is required to leverage these issues.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: firstname.lastname@example.org <mailto:email@example.com>.