vendor:
Pragyan CMS
by:
Steffen Rösemann
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Pragyan CMS
Affected Version From: Pragyan CMS v.3
Affected Version To: Pragyan CMS v.3
Patch Exists: YES
Related CWE: -
CPE: a:delta:pragyan
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Advisory: SQL injection vulnerability in Pragyan CMS v.3.0
Pragyan CMS v. 3 suffers from a SQL injection vulnerability that can be abused even by unauthenticated attackers.
Mitigation:
Vendor notified, did not respond after initial communication. If you use Pragyan CMS v.3, please locate the file userprofile.lib.php and use my patch (see [5], usage at your own risk!).