PT-2017-6710 · Genixcms · Genixcms

Cfreer

·

Published

2017-11-08

·

Updated

2022-05-17

·

CVE-2015-3933

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeniXCMS versions prior to 0.0.3-patch
Description The issue concerns SQL injection vulnerabilities in the inc/lib/User.class.php file. Remote attackers can execute arbitrary SQL commands via the email parameter or the userid parameter to the "register.php" endpoint.
Recommendations For versions prior to 0.0.3-patch, update to version 0.0.3-patch or later to resolve the issue. As a temporary workaround, consider restricting access to the "register.php" endpoint to minimize the risk of exploitation. Avoid using the email and userid parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3933
GHSA-Q4HW-62MX-Q37W

Affected Products

Genixcms