Polterguy · Phosphorus Five · CVE-2018-25070
**Name of the Vulnerable Software and Affected Versions**
polterguy Phosphorus Five versions up to 8.2
**Description**
A critical issue has been found that affects the `csv.Read` function of the CSV Import component, specifically in the file `plugins/extras/p5.mysql/NonQuery.cs`. This issue leads to sql injection.
**Recommendations**
For versions up to 8.2, upgrade to version 8.3 to address this issue.
As a temporary workaround, consider restricting the use of the `csv.Read` function in the CSV Import component until the upgrade is applied.