Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 81.1%