SQL Injection Vulnerability in SEMCMS v4.8 by SEMCMS
CVE-2023-48864

7.5HIGH

Key Information:

Vendor

SEMCMS

Status
Vendor
CVE Published:
10 January 2024

What is CVE-2023-48864?

SEMCMS v4.8 has been identified with a security flaw involving SQL injection through the languageID parameter located in the /web_inc.php file. This vulnerability allows an attacker to manipulate SQL queries, potentially gaining unauthorized access to sensitive data, altering database operations, and executing arbitrary commands. Addressing this issue is essential for maintaining the integrity and security of systems utilizing SEMCMS. It is crucial for users to review their implementations and apply appropriate security measures to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.