PT-2022-22454 · Pligg Cms · Pligg Cms

Xiaoxianghuayuo

·

Published

2022-08-02

·

Updated

2022-08-04

·

CVE-2022-34955

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pligg CMS version 2.0.2
Description A time-based SQL injection issue was found in Pligg CMS via the page size parameter at the "load data for topusers.php" endpoint.
Recommendations For Pligg CMS version 2.0.2, consider restricting access to the "load data for topusers.php" endpoint until a patch is available. Avoid using the page size parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-34955

Affected Products

Pligg Cms