SQL Injection Vulnerability in CMS Made Simple by CMS Made Simple, Inc.
CVE-2021-28999
8.8HIGH
What is CVE-2021-28999?
A SQL Injection vulnerability exists in CMS Made Simple versions up to 2.2.15, allowing remote attackers to execute arbitrary commands through the m1_sortby parameter within the modules/News/function.admin_articlestab.php file. This flaw can potentially compromise the integrity and security of the affected system by enabling unauthorized access to sensitive database information.