PT-2025-50759 · Csz Cms · Csz Cms
Abdulaziz Almetairy
·
Published
2025-12-11
·
Updated
2025-12-12
·
CVE-2024-58307
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CSZCMS version 1.3.0
Description
The software contains an authenticated SQL injection issue in the members view functionality. Authenticated attackers can manipulate database queries by injecting malicious SQL code through the
view parameter. This allows for time-based blind SQL injection attacks, potentially leading to the extraction of database information. The affected API endpoint is the members view endpoint.Recommendations
Apply a fix for CSZCMS version 1.3.0 to address the SQL injection issue. As a temporary workaround, restrict access to the members view functionality to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Csz Cms