Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-00001
HistoryDec 27, 2022 - 12:00 a.m.

AeroCMS SQL Injection Vulnerability (CNVD-2023-00001)

2022-12-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
aerocms
sql injection
vulnerability
approve parameter
web form
exploit
sql command
server

EPSS

0.001

Percentile

37.9%

AeroCMS is a content management system from AeroCMS, Inc. AeroCMS v0.0.1 contains a SQL injection vulnerability, which stems from the vulnerability of the Approve parameter of the CMS system to SQL injection attacks. An attacker could exploit the vulnerability by inserting SQL commands into a Web form submission or query string of an input domain or page request, eventually reaching the point of tricking the server into executing a malicious SQL command.

EPSS

0.001

Percentile

37.9%

Related for CNVD-2023-00001