NavigateCMS / Navigate-CMS

Navigate CMS, a very powerful open source content management system for everybody.
http://www.navigatecms.com
GNU General Public License v2.0
8 stars 4 forks source link

Blind SQL Injection Vulnerability Navigate CMS 2.9 #20

Closed luuthehienhbit closed 4 years ago

luuthehienhbit commented 4 years ago

Expected behaviour Blind SQL injection (SQLi) enforced to an injection attack wherein an attacker can execute malicious Blind SQL used to collect information via URL encoded GET input category. Impact Depending on the backend database, the database connection settings, and the operating system, an attacker can mount one or more of the following attacks successfully:

NavigateCMS commented 4 years ago

Fixed by d459b1d151350b401236e0a7f746c82a8fa80562