This advisory describes a SQL injection vulnerability in SelfComposer CMS, where input parameters like 'idprod' and 'idpadrerif' are not properly sanitized. It provides URLs demonstrating the vulnerability but does not include functional exploit code.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target:SelfComposer CMS
No auth needed
Prerequisites:Access to vulnerable SelfComposer CMS instance