Jump to content

WHMCS Admin details showed in cliend Company field


Netix

Recommended Posts

Hello,

i have got this email:

 

Client ID: XXXX has requested to change his/her details as indicated below:

Company Name: '' to 'AES_ENCRYPT(1,1), companyname=((SELECT GROUP_CONCAT(id,0x3a,username,0x3a,email,0x3a,password SEPARATOR 0x2c20) FROM tbladmins))'

Default Payment Method: '' to ''

If you are unhappy with any of the changes, you need to login and revert them - this is the only record of the old details.

 

and when i am go to client details i see admin emails and encrypted passwords in company name filed of this client.

Is this normal that field can run SQL query or there is problem with my configuration?

 

Thanx

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated