Allowed Sql injection in usersearch.php, which isn't a big issue because you can only access it when you're admin anyway.
Replace the file admin/pages/useredit.php with a newer version.
admin/pages/useredit.php
Impact
Allowed Sql injection in usersearch.php, which isn't a big issue because you can only access it when you're admin anyway.
Workarounds
Replace the file
admin/pages/useredit.phpwith a newer version.