PT-2026-5163 · Smartdatasoft · Smartblog

C0Wnuts

·

Published

2026-01-28

·

Updated

2026-02-09

·

CVE-2020-36972

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SmartBlog version 2.0.1
Description The software contains a blind SQL injection issue in the id post parameter of the details controller. This allows attackers to extract database information by injecting crafted SQL queries that compare database contents character-by-character. The affected parameter is id post and is part of the details controller.
Recommendations Apply a fix for SmartBlog version 2.0.1 to address the SQL injection issue in the id post parameter of the details controller.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36972

Affected Products

Smartblog