First published: Thu May 26 2022(Updated: )
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chshcms Cscms Music Portal System | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-29687.
Version 4.2 of the CSCMS Music Portal System is affected by this vulnerability.
The severity of this vulnerability is high with a CVSS score of 7.2.
The vulnerability occurs due to a blind SQL injection in the id parameter of the /admin.php/user/level_del endpoint.
At the moment, there is no official fix available for this vulnerability. It is recommended to follow the recommendations provided by the software vendor or the security community.