npm›flintcms›CVE-2018-37839.8 CRITICALSQL InjectionA privilege escalation detected in flintcms allows account takeover due to blind MongoDB injection in password reset.