github.com
https://github.com/CuppaCMS/CuppaCMS/issues/17 CVE-2022-24266
HIGHNuclei
Cuppa CMS v1.0 - SQL injection
Record summary
CVE-2022-24266 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHCuppa CMS v1.0 - SQL injectionCVSS 7.5
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire system.
Remediation
Upgrade to the latest version of Cuppa CMS or apply the provided patch to fix the SQL injection vulnerability.
WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022sqlicuppaauthenticatedcuppacmsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:cuppacms:cuppacms:1.0:*:*:*:*:*:*:*
https://github.com/CuppaCMS/CuppaCMS https://nvd.nist.gov/vuln/detail/CVE-2022-24266 https://github.com/CuppaCMS/CuppaCMS/issues/17 https://github.com/truonghuuphuc/CVE https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
3github.com
https://github.com/truonghuuphuc/CVE nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-24266