Record summary

CVE-2020-37110 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated user input. Attackers can exploit vulnerable query parameters like 'title' to inject malicious SQL code and potentially extract or modify database contents. This issue does not involve cross-site scripting.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.5.2affected

Proofs of concept

1

Catalogued exploits

ExploitDB60CycleCMS - 'news.php' SQL InjectionExploitDB exploitby Unkn0wnNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

4