Showing 1 vulnerability on this page for FreeSMS

Signals CISA KEV Ransomware Nuclei
Freesms vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

FreeSMS 2.1.2 Authentication Bypass via SQL Injection

FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login endpoint. Attackers can exploit the vulnerable password parameter in requests to /pages/crc_handler.php?method=login to authenticate as any known user and subsequently modify their password via the profile update function.

CWE-89Mar 4, 2026
CVSS8.8v4.0EPSS0.453%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX