CVE-2012-0999

lepton < 1.1.4 - SQL Injection via group_id Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.

References (3)

Core 3
Core References

Scores

EPSS 0.0129
EPSS Percentile 67.4%

Details

CWE
CWE-89
Status published
Products (4)
lepton-cms/lepton 1.1.0
lepton-cms/lepton 1.1.1
lepton-cms/lepton 1.1.2
lepton-cms/lepton < 1.1.3
Published Feb 24, 2012
Tracked Since Feb 18, 2026