SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
CVSS Metrics