Record summary

CVE-2022-24265 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHCuppa CMS v1.0 - SQL injectionCVSS 7.5

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire CMS system.

Remediation

Upgrade to the latest version of Cuppa CMS or apply the provided patch to fix the SQL injection vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicve2022cvesqlicuppaauthenticatedcuppacmsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:cuppacms:cuppacms:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3