Newpk · Newpk · CVE-2020-20189
**Name of the Vulnerable Software and Affected Versions**
NewPK version 1.1
**Description**
The issue is related to a SQL Injection vulnerability. It can be exploited via the `title` parameter to the "admin
ewpost.php" API endpoint.
**Recommendations**
For NewPK version 1.1, avoid using the `title` parameter in the "admin
ewpost.php" endpoint until the issue is resolved. Consider temporarily restricting access to this endpoint to minimize the risk of exploitation.