CVE-2014-1597 | i-doit up to 1.2.4 objID sql injection (EDB-39096 / XFDB-91269)
A vulnerability, which was classified as critical, was found in i-doit up to 1.2.4. Affected is an unknown function. The manipulation of the argument objID leads to sql injection.
This vulnerability is traded as CVE-2014-1597. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.