First published: Thu May 26 2022(Updated: )
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chshcms Cscms Music Portal System | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29683 is a blind SQL injection vulnerability discovered in CSCMS Music Portal System v4.2.
The blind SQL injection vulnerability in CSCMS Music Portal System v4.2 is triggered via the id parameter at /admin.php/Label/page_del, allowing an attacker to manipulate the SQL queries and potentially retrieve or modify sensitive data.
The severity of CVE-2022-29683 is rated as high with a CVSS score of 7.2.
To mitigate the blind SQL injection vulnerability in CSCMS Music Portal System v4.2, it is recommended to apply the latest security patches provided by the vendor.
More information about CVE-2022-29683 can be found at the following reference: [GitHub](https://github.com/chshcms/cscms/issues/34#issue-1209056912).