First published: Thu Aug 10 2023(Updated: )
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39805 is a SQL injection vulnerability in iCMS v7.0.16.
CVE-2023-39805 has a severity rating of 9.8, which is considered critical.
CVE-2023-39805 affects iCMS v7.0.16 and allows SQL injection via the 'where' parameter in admincp.php.
To fix CVE-2023-39805, it is recommended to update iCMS to a version that has the SQL injection vulnerability patched.
More information about CVE-2023-39805 can be found at the following references: [http://icms.com](http://icms.com), [http://icmsdev.com](http://icmsdev.com), and [https://gist.github.com/ChubbyZ/3ad434bd5fc2ab1242dd32500384cfb5](https://gist.github.com/ChubbyZ/3ad434bd5fc2ab1242dd32500384cfb5).