PT-2022-27469 · Aerocms · Aerocms

Published

2022-11-22

·

Updated

2025-04-25

·

CVE-2022-45330

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AeroCMS version 0.0.1
Description The issue allows attackers to access database information through a SQL Injection vulnerability via the Category parameter at the "category.php" endpoint. This vulnerability enables unauthorized access to sensitive database information.
Recommendations For AeroCMS version 0.0.1, consider restricting access to the "category.php" endpoint until a patch is available. As a temporary workaround, avoid using the Category parameter in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-45330

Affected Products

Aerocms