PT-2026-5163 · Smartdatasoft · Smartblog

C0Wnuts

·

Publicado

2026-01-28

·

Atualizado

2026-02-09

·

CVE-2020-36972

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SmartBlog version 2.0.1
Description The software contains a blind SQL injection issue in the id post parameter of the details controller. This allows attackers to extract database information by injecting crafted SQL queries that compare database contents character-by-character. The affected parameter is id post and is part of the details controller.
Recommendations Apply a fix for SmartBlog version 2.0.1 to address the SQL injection issue in the id post parameter of the details controller.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-36972

Produtos afetados

Smartblog