Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-58301

Опубликовано: 11 дек. 2025
Источник: nvd
EPSS Низкий

Описание

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.

EPSS

Процентиль: 12%
0.00041
Низкий

Дефекты

CWE-89

Связанные уязвимости

github
около 2 месяцев назад

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.

EPSS

Процентиль: 12%
0.00041
Низкий

Дефекты

CWE-89