CVE-2024-25227
CRITICALabo.cms 5.8 - SQL Injection via tb_login Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-25227. PoCs published by thetrueartist.
AI-analyzed exploit summary This PoC demonstrates an unauthenticated SQL injection vulnerability in ABO.CMS 5.8 via the 'tb_login' parameter, allowing login bypass by injecting a tautology (e.g., '2579=2579') to bypass authentication checks.
Description
SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.
Exploits (2)
This PoC demonstrates an unauthenticated SQL injection vulnerability in ABO.CMS 5.8 via the 'tb_login' parameter, allowing login bypass by injecting a tautology (e.g., '2579=2579') to bypass authentication checks.
This repository contains a writeup describing an unauthenticated SQL injection vulnerability (CVE-2024-25227) in ABO.CMS 5.8, affecting the 'tb_login' parameter on the admin login page. The vulnerability supports multiple SQLi techniques, including boolean-based blind, error-based, stacked queries, time-based blind, and union queries.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H