Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9739-cp23-84gj

Опубликовано: 07 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.

b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.

EPSS

Процентиль: 70%
0.00621
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.

EPSS

Процентиль: 70%
0.00621
Низкий

Дефекты

CWE-89