Vulnerability Description
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 74Cms | 74Cms | 5.2.8 |
Related Weaknesses (CWE)
References
- https://github.com/Ers4tz/vuln/blob/master/74cms_5.2.8_SQLI.mdExploitThird Party Advisory
- https://github.com/Ers4tz/vuln/blob/master/74cms_5.2.8_SQLI.mdExploitThird Party Advisory
FAQ
What is CVE-2019-17612?
CVE-2019-17612 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort...
How severe is CVE-2019-17612?
CVE-2019-17612 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17612?
Check the references section above for vendor advisories and patch information. Affected products include: 74Cms 74Cms.