vendor:
Symphony CMS
by:
Sachin Wagh
9
CVSS
HIGH
Multiple SQL Injection Vulnerabilities
89
CWE
Product Name: Symphony CMS
Affected Version From: Symphony CMS 2.6.3
Affected Version To: Symphony CMS 2.6.4
Patch Exists: YES
Related CWE: N/A
CPE: a:getsymphony:symphony_cms:2.6.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2020
Symphony CMS 2.6.3 – Multiple SQL Injection Vulnerabilities
Symphony CMS 2.6.3 is vulnerable to multiple SQL injection vulnerabilities. These vulnerabilities can be exploited by remote attackers to gain access to sensitive information stored in the database. An attacker can exploit these vulnerabilities by sending specially crafted requests to the vulnerable application. The vulnerable parameters are 'fields[username]', 'action[save]' and 'fields[email]' of the '/symphony/system/authors/new/' page.
Mitigation:
Upgrade to Symphony CMS 2.6.5 or later.