ZSA-2024-03
A logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.
Thanks to Martino Spagnuolo for reporting.
A logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.
Thanks to Martino Spagnuolo for reporting.