PT-2024-4033 · Cu Solutions · Cu Solutions Group Content Management System
Emily Gosney
·
Published
2024-02-12
·
Updated
2024-08-29
·
CVE-2023-48987
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CU Solutions Group (CUSG) Content Management System (CMS) versions prior to 7.75
Description
The issue is related to a Blind SQL Injection vulnerability in the pages.php component, which can be exploited by a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information. This is due to the lack of protection measures for the SQL query structure.
Recommendations
For versions prior to 7.75, update to version 7.75 or later to resolve the issue.
As a temporary workaround, consider restricting access to the pages.php component until a patch is available.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cu Solutions Group Content Management System