SQL Injection Vulnerability in EasyCMS by EasyCMS
CVE-2022-23358
9.8CRITICAL
What is CVE-2022-23358?
EasyCMS version 1.6 is susceptible to SQL injection attacks due to unsanitized user input in the ArticlemAction.class.php component. When users enter search terms, these terms are directly utilized to formulate SQL statements in the background without proper validation. This flaw allows attackers to manipulate database queries, potentially exposing sensitive information or compromising the integrity of the underlying database.
