Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.064
EPSS Ranking 91.1%