CVE-2022-23358

EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:easycms:easycms:1.6:*:*:*:*:*:*:*

Information

Published : 2022-02-16 04:15

Updated : 2022-02-23 13:23


NVD link : CVE-2022-23358

Mitre link : CVE-2022-23358


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

easycms

  • easycms