No-Cms 1.0 SQL Injection via order_by Parameter
Vulnerability Description
No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious SQL code in the order_by[0] parameter to extract sensitive database information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25431
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Loading Kura Kura
Affected Vendor
goFrendiAsgard
View all reports →