Blind SQL Injection in SmartBlog by SmartDataSoft
CVE-2020-36972
Key Information:
- Vendor
Smartdatasoft
- Status
- Vendor
- CVE Published:
- 28 January 2026
Badges
What is CVE-2020-36972?
SmartBlog version 2.0.1 contains a vulnerability in the 'id_post' parameter of its details controller, which is susceptible to blind SQL injection. This allows attackers to execute crafted SQL queries that can sequentially extract sensitive data from the database by comparing each character returned. Exploiting this flaw can lead to unauthorized access to database information, posing significant risks to web application integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SmartBlog 2.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
