CVE-2014-8999

XOOPS < 2.5.6 - Authenticated SQL Injection via selgroups Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter.

References (4)

Core 4
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/39
Vendor Advisory x_refsource_confirm
http://xoops.org/modules/news/article.php?storyid=6658
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71117

Scores

EPSS 0.0166
EPSS Percentile 74.2%

Details

CWE
CWE-89
Status published
Products (1)
xoops/xoops < 2.5.6
Published Nov 20, 2014
Tracked Since Feb 18, 2026