First published: Sat Nov 17 2018(Updated: )
An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in S-CMS v1.5 is CVE-2018-19331.
The severity of CVE-2018-19331 is high with a score of 7.5.
The affected software version of CVE-2018-19331 is S-CMS v1.5.
The CWE number associated with CVE-2018-19331 is CWE-89 (SQL Injection).
Yes, a proof of concept for CVE-2018-19331 is available at the following link: https://kingflyme.blogspot.com/2018/11/the-poc-of-s-cmssql-injection.html.