Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwv7-wwg8-6rjj

Опубликовано: 03 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated user input. Attackers can exploit vulnerable query parameters like 'title' to inject malicious SQL code and potentially extract or modify database contents. This issue does not involve cross-site scripting.

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated user input. Attackers can exploit vulnerable query parameters like 'title' to inject malicious SQL code and potentially extract or modify database contents. This issue does not involve cross-site scripting.

EPSS

Процентиль: 9%
0.00033
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.2
nvd
5 дней назад

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated user input. Attackers can exploit vulnerable query parameters like 'title' to inject malicious SQL code and potentially extract or modify database contents. This issue does not involve cross-site scripting.

EPSS

Процентиль: 9%
0.00033
Низкий

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89