PT-2022-16310 · Tuzicms · Tuzicms

Vikt0R101

·

Published

2022-03-28

·

Updated

2022-03-31

·

CVE-2022-23882

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TuziCMS version 2.0.6
Description The issue is related to SQL injection in the BannerController.class.php file, located at AppManageController. This affects the ability to securely manage data.
Recommendations For TuziCMS version 2.0.6, consider restricting access to the BannerController.class.php file until a patch is available. As a temporary workaround, avoid using the BannerController class until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23882

Affected Products

Tuzicms