SQL Injection Vulnerability in SEMCMS Affecting Version 4.8
CVE-2024-36800

7.5HIGH

Key Information:

Vendor

SEMCMS

Status
Vendor
CVE Published:
4 June 2024

What is CVE-2024-36800?

A SQL injection vulnerability exists in SEMCMS version 4.8, allowing remote attackers to exploit the ID parameter in Download.php. This vulnerability could potentially lead to unauthorized access to sensitive information stored within the application's database. Attackers leveraging this vulnerability might execute arbitrary SQL queries, allowing them to manipulate, extract, or delete data from the database. Organizations using this version of SEMCMS should prioritize applying necessary security updates and patches to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.