CVE-2013-3727

Kasseler-cms < 2 - SQL Injection

Title source: rule

Description

SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/26623

Scores

EPSS 0.0217
EPSS Percentile 84.4%

Details

CWE
CWE-89
Status published
Products (1)
kasseler-cms/kasseler-cms < 2
Published Mar 13, 2014
Tracked Since Feb 18, 2026