Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vwqp-gjpc-g89c

Опубликовано: 10 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

EPSS

Процентиль: 80%
0.01318
Низкий

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

EPSS

Процентиль: 80%
0.01318
Низкий

8.8 High

CVSS3

Дефекты

CWE-89