SQL Injection Vulnerability in SEMCMS Product
CVE-2024-36801

5.9MEDIUM

Key Information:

Vendor

SEMCMS

Status
Vendor
CVE Published:
4 June 2024

What is CVE-2024-36801?

A security vulnerability in SEMCMS v.4.8 enables a remote attacker to exploit the SQL injection flaw via the lgid parameter in the Download.php script. This weakness can lead to unauthorized access to sensitive information stored in the database, posing significant risks to data integrity and confidentiality. It is crucial for users to implement security measures to mitigate the potential impact of this vulnerability.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-36801 : SQL Injection Vulnerability in SEMCMS Product