SQL Injection Vulnerability in SEMCMS Affecting Version 4.8
CVE-2024-36800
7.5HIGH
What is CVE-2024-36800?
A SQL injection vulnerability exists in SEMCMS version 4.8, allowing remote attackers to exploit the ID parameter in Download.php. This vulnerability could potentially lead to unauthorized access to sensitive information stored within the application's database. Attackers leveraging this vulnerability might execute arbitrary SQL queries, allowing them to manipulate, extract, or delete data from the database. Organizations using this version of SEMCMS should prioritize applying necessary security updates and patches to mitigate the risks associated with this vulnerability.