CVE-2015-3933
CRITICALMetalGenix GeniXCMS <0.0.3-patch - SQL Injection
Title source: llmDescription
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0243
EPSS Percentile
85.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (2)
genix/cms
0Packagist
metalgenix/genixcms
< 0.0.3
Published
Nov 08, 2017
Tracked Since
Feb 18, 2026