Smartdatasoft · Smartblog · CVE-2020-36972
**Name of the Vulnerable Software and Affected Versions**
SmartBlog version 2.0.1
**Description**
The software contains a blind SQL injection issue in the `id post` parameter of the details controller. This allows attackers to extract database information by injecting crafted SQL queries that compare database contents character-by-character. The affected parameter is `id post` and is part of the details controller.
**Recommendations**
Apply a fix for SmartBlog version 2.0.1 to address the SQL injection issue in the `id post` parameter of the details controller.