nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58307 CVE-2024-58307
CRITICAL
CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
Record summary
CVE-2024-58307 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CSZCMSBrowse cszcms / CSZCMSDefault status: unaffected | CVE List | 1.3.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCSZCMS v1.3.0 - SQL Injection (Authenticated)ExploitDB exploitby Abdulaziz AlmetairyNot analyzed1 file
References
5CSZCMS Download Pageproduct
https://sourceforge.net/projects/cszcms/files/install/CSZCMS-V1.3.0.zip/download CSZCMS Homepageproduct
https://www.cszcms.com/ ExploitDB-51916exploit
https://www.exploit-db.com/exploits/51916 VulnCheck Advisory: CSZCMS 1.3.0 Authenticated SQL Injection via Members View EndpointThird-party advisory
https://www.vulncheck.com/advisories/cszcms-authenticated-sql-injection-via-members-view-endpoint