Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgp5-7jww-4753

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 8.8

Описание

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

EPSS

Процентиль: 24%
0.00082
Низкий

9.3 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

EPSS

Процентиль: 24%
0.00082
Низкий

9.3 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89