CVE-2024-45265
CRITICALSkySystem Arfa-CMS <5.1.3124 - SQL Injection
Title source: llmDescription
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.1758
EPSS Percentile
95.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-79
CWE-89
Status
published
Products (1)
skyss/arfa-cms
< 5.1.3132
Published
Aug 26, 2024
Tracked Since
Feb 18, 2026