CVE-2022-24265: SQL Injection
Published Jan 31, 2022
·Updated
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menufilter=3 parameter.
Affected Software
1 affected component
CuppaCMS CuppaCMS=1.0
Event History
Jan 31, 2022
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-24265?
CVE-2022-24265 has been classified as a high severity vulnerability due to its potential for SQL injection exploitation.
2
How do I fix CVE-2022-24265?
To fix CVE-2022-24265, update Cuppa CMS to version 1.1 or later to mitigate the SQL injection vulnerability.
3
What are the potential impacts of CVE-2022-24265?
Exploitation of CVE-2022-24265 may allow an attacker to manipulate SQL queries, potentially leading to unauthorized access to sensitive data.
4
Which software versions are affected by CVE-2022-24265?
CVE-2022-24265 affects Cuppa CMS version 1.0.
5
What is the nature of the vulnerability in CVE-2022-24265?
CVE-2022-24265 is a SQL injection vulnerability found in the menu component of Cuppa CMS.