ZeroHour

CVE-2022-23358

PoC
CVSS 3.1
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.

Vendors
easycms
Products
easycms
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.