|Topic:||SQL injection vulnerability in user upload|
|Versions affected:||< 1.9.13 (2.x not affected)|
|Reported by:||Matt Meisberger|
|Solution:||upgrade to 1.9.13|
|Workaround:||escape quotes in user upload CSV files|
When uploading a CSV file with group names that contain quotes, this could throw off SQL processing. This is only exploitable by admins, but could accidentally lead to DB corruption.