cuppa.com
http://cuppa.com/ CVE-2022-27984
CRITICALNuclei
Cuppa CMS v1.0 - SQL injection
Record summary
CVE-2022-27984 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALCuppa CMS v1.0 - SQL injectionCVSS 9.8
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire CMS system.
Remediation
Apply the latest patch or upgrade to a newer version of Cuppa CMS that addresses the SQL injection vulnerability (CVE-2022-27984).
WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022sqlicuppaauthenticatedcuppacmsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:cuppacms:cuppacms:1.0:*:*:*:*:*:*:*
https://github.com/CuppaCMS/CuppaCMS https://nvd.nist.gov/vuln/detail/CVE-2022-27984 https://www.cuppacms.com/ http://cuppa.com/
Source: ProjectDiscovery
References
4github.com
https://github.com/CuppaCMS/CuppaCMS/issues/30 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-27984 cuppacms.comProduct
https://www.cuppacms.com/