Record summary

CVE-2021-3018 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 25, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBIPeakCMS 3.5 - Boolean-based blind SQLiExploitDB exploitby MoeAlBarbariNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALIPeakCMS 3.5 - SQL InjectionCVSS 9.8

ipeak Infosystems ibexwebCMS 3.5 contains an unauthenticated Boolean-based SQL injection caused by unsanitized 'id' parameter in /cms/print.php, letting attackers execute arbitrary SQL commands, exploit requires no authentication.

Impact

Attackers can execute arbitrary SQL commands, potentially leading to data disclosure, data tampering, or full database compromise.

Remediation

Apply the latest security patches or update to a version that fixes this vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagscvecve2021ipeakcmscmssqliunauthvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ipeak:ipeakcms:3.5:*:*:*:*:*:*:*
FOFA: body="ipeak" && body="3.5"

Source: ProjectDiscovery

References

6