Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g4c-4qm2-q7cv

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.

EPSS

Процентиль: 12%
0.00041
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
около 2 месяцев назад

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.

EPSS

Процентиль: 12%
0.00041
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89