PT-2022-11887 · Csz Cms · Csz Cms

Rahad Chowdhury

·

Published

2022-03-29

·

Updated

2022-04-05

·

CVE-2021-43701

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CSZ CMS version 1.2.9
Description The issue is related to a Time and Boolean-based Blind SQL Injection. This occurs in the /admin/export/getcsv/article db endpoint, specifically through the fieldS[] and orderby parameters.
Recommendations For CSZ CMS version 1.2.9, avoid using the fieldS[] and orderby parameters in the /admin/export/getcsv/article db endpoint until a fix is available. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43701

Affected Products

Csz Cms