SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.
https://www.exploit-db.com/exploits/3932
https://exchange.xforce.ibmcloud.com/vulnerabilities/34308