First published: Tue Apr 26 2022(Updated: )
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27985 is considered a critical SQL injection vulnerability that can be exploited to compromise the database of CuppaCMS.
To fix CVE-2022-27985, you should update CuppaCMS to the latest version that addresses this SQL injection vulnerability.
CVE-2022-27985 specifically affects CuppaCMS version 1.0.
CVE-2022-27985 can enable attackers to execute arbitrary SQL commands, leading to data leakage, data manipulation, or database takeover.
If an immediate update is not possible, consider implementing web application firewall rules to help filter out malicious SQL injection attempts targeting CVE-2022-27985.