First published: Wed May 04 2022(Updated: )
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chshcms Cscms | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-28552 is high with a severity value of 8.8
The affected software for CVE-2022-28552 is Cscms 4.1
CVE-2022-28552 manifests as a SQL Injection vulnerability
To reproduce the vulnerability in Cscms 4.1, log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.
At the moment, there is no known fix available for CVE-2022-28552. It is recommended to follow the references provided for any updates on a possible fix.