CVE-2022-27984: SQL Injection
Published Apr 26, 2022
·Updated
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menufilter parameter at /administrator/templates/default/html/windows/right.php.
Affected Software
1 affected component
CuppaCMS CuppaCMS=1.0
Event History
Apr 26, 2022
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-27984?
The severity of CVE-2022-27984 is critical with a CVSS score of 9.8.
2
How do I fix the SQL injection vulnerability in CuppaCMS v1.0 (CVE-2022-27984)?
To fix the SQL injection vulnerability, update CuppaCMS to a secure version and sanitize user input in the menu_filter parameter.
3
Where was the SQL injection vulnerability found in CuppaCMS v1.0 (CVE-2022-27984)?
The SQL injection vulnerability was found in the menu_filter parameter at /administrator/templates/default/html/windows/right.php in CuppaCMS v1.0.