Description
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.
References (3)
Core 3
Core References
Various Sources x_refsource_confirm
http://www.lepton-cms.org/media/changelog/changelog_1.1.4.txt
Patch, Vendor Advisory x_refsource_confirm
http://www.lepton-cms.org/posts/security-release-lepton-1.1.4-52.php
Exploit x_refsource_misc
https://www.htbridge.ch/advisory/HTB23072
Scores
EPSS
0.0129
EPSS Percentile
67.4%
Details
CWE
CWE-89
Status
published
Products (4)
lepton-cms/lepton
1.1.0
lepton-cms/lepton
1.1.1
lepton-cms/lepton
1.1.2
lepton-cms/lepton
< 1.1.3
Published
Feb 24, 2012
Tracked Since
Feb 18, 2026