Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwq9-3w37-xj9v

Опубликовано: 17 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.

EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.

EPSS

Процентиль: 50%
0.00264
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.

EPSS

Процентиль: 50%
0.00264
Низкий

Дефекты

CWE-89