Product
mooSocial versions up to 3.2.4 are vulnerable to remote SQL injection via the rating argument in the /stores/all-products endpoint, with public exploit code currently available.