vendor:
CSZ CMS
by:
Dogukan Dincer
7.5
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: CSZ CMS
Affected Version From: 1.3.2000
Affected Version To: 1.3.2000
Patch Exists: NO
Related CWE:
CPE: a:cszcms:csz_cms:1.3.0
Platforms Tested: Kali Linux, Windows 10, PHP 7.2.4, Apache 2.4
2021
CSZ CMS 1.3.0 – ‘Multiple’ Blind SQLi
CSZ CMS 1.3.0 is vulnerable to Blind SQL Injection. By entering the ' character in the search section, it is determined that the 'p' parameter creates the vulnerability. Databases can be accessed with manual or automated tools.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.