CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
Vulnerability Description
CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58307
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Abdulaziz Almetairy
References
More from cszcms
View All →Affected Vendor
cszcms
View all reports →