CVE-2024-28389: Knowband Spinwheel
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.
Affected products
- Knowband Spinwheel: version 3.0.3 only
Published 2024-03-19. Last modified 2026-06-17.