Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2326-jr9x-m329

Опубликовано: 30 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

EPSS

Процентиль: 8%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
nvd
6 дней назад

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

EPSS

Процентиль: 8%
0.00031
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89