Unknown · Rizalafani Cms-Php · CVE-2021-35284
**Name of the Vulnerable Software and Affected Versions**
rizalafani cms-php version 1
**Description**
The issue is related to a SQL Injection vulnerability in the `get user` function located in `login manager.php`. This vulnerability allows for potential SQL injection attacks.
**Recommendations**
For rizalafani cms-php version 1, consider disabling the `get user` function in `login manager.php` until a patch is available to prevent potential SQL injection attacks. Restrict access to the `login manager.php` file to minimize the risk of exploitation. Avoid using user-input data directly in SQL queries to prevent injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.