CVE-2024-25227

CRITICAL

abo.cms 5.8 - SQL Injection via tb_login Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-25227. PoCs published by thetrueartist.

AI-analyzed exploit summary This PoC demonstrates an unauthenticated SQL injection vulnerability in ABO.CMS 5.8 via the 'tb_login' parameter, allowing login bypass by injecting a tautology (e.g., '2579=2579') to bypass authentication checks.

Description

SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.

Exploits (2)

nomisec WORKING POC
by thetrueartist · poc
https://github.com/thetrueartist/ABO.CMS-EXPLOIT-Unauthenticated-Login-Bypass-CVE-2024-25227

This PoC demonstrates an unauthenticated SQL injection vulnerability in ABO.CMS 5.8 via the 'tb_login' parameter, allowing login bypass by injecting a tautology (e.g., '2579=2579') to bypass authentication checks.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: ABO.CMS 5.8
No auth needed
Prerequisites: Access to the login page of ABO.CMS 5.8
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by thetrueartist · poc
https://github.com/thetrueartist/ABO.CMS-Login-SQLi-CVE-2024-25227

This repository contains a writeup describing an unauthenticated SQL injection vulnerability (CVE-2024-25227) in ABO.CMS 5.8, affecting the 'tb_login' parameter on the admin login page. The vulnerability supports multiple SQLi techniques, including boolean-based blind, error-based, stacked queries, time-based blind, and union queries.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: ABO.CMS 5.8
No auth needed
Prerequisites: Access to the admin login page of ABO.CMS 5.8
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0079
EPSS Percentile 51.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
abocms/abo.cms 5.8
Published Mar 15, 2024
Tracked Since Feb 18, 2026