First published: Mon Nov 26 2018(Updated: )
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | <2018-11-12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19559 is considered a medium severity vulnerability due to its potential for SQL Injection attacks.
To fix CVE-2018-19559, update CuppaCMS to the version released after November 12, 2018.
CVE-2018-19559 affects all versions of CuppaCMS prior to November 12, 2018.
CVE-2018-19559 is classified as an SQL Injection vulnerability.
CVE-2018-19559 could allow attackers to execute arbitrary SQL queries, potentially compromising the database and sensitive data.