CVE-2024-58307
HIGHCSZCMS 1.3.0 - Authenticated SQL Injection via Members View Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-58307. PoCs published by Abdulaziz Almetairy.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in CSZCMS v1.3.0. The attacker modifies the 'id' parameter in a GET request to inject a sleep-based SQL payload, confirming the vulnerability.
Description
CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in CSZCMS v1.3.0. The attacker modifies the 'id' parameter in a GET request to inject a sleep-based SQL payload, confirming the vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H