Описание
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.8:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.92556
Критический
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
EPSS
Процентиль: 100%
0.92556
Критический
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-89