PT-2024-4033 · Cu Solutions · Cu Solutions Group Content Management System

Emily Gosney

·

Published

2024-02-12

·

Updated

2024-08-29

·

CVE-2023-48987

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions CU Solutions Group (CUSG) Content Management System (CMS) versions prior to 7.75
Description The issue is related to a Blind SQL Injection vulnerability in the pages.php component, which can be exploited by a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information. This is due to the lack of protection measures for the SQL query structure.
Recommendations For versions prior to 7.75, update to version 7.75 or later to resolve the issue. As a temporary workaround, consider restricting access to the pages.php component until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-04469
CVE-2023-48987

Affected Products

Cu Solutions Group Content Management System