vendor:
NoviSmart CMS
by:
n1x_ [MS-WEB]
7.5
CVSS
HIGH
SQL injection
89
CWE
Product Name: NoviSmart CMS
Affected Version From: Every version
Affected Version To: Every version
Patch Exists: NO
Related CWE: CWE-89
CPE: a:novismart:novismart_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
NoviSmart CMS SQL injection
An attacker can inject malicious SQL code into the Referer HTTP header field of a GET request to the NoviSmart CMS, which can be used to gain unauthorized access to the system.
Mitigation:
Input validation should be used to prevent SQL injection attacks.