Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.
References
Link | Resource |
---|---|
https://gist.github.com/Mr-Akuma/8d84b564fb051caa1b1ea31b24f6b9fb | Exploit Third Party Advisory |
https://moderncampus.com/products/web-content-management.html | Product Vendor Advisory |
https://gist.github.com/Mr-Akuma/8d84b564fb051caa1b1ea31b24f6b9fb | Exploit Third Party Advisory |
https://moderncampus.com/products/web-content-management.html | Product Vendor Advisory |
Configurations
History
21 Nov 2024, 07:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/Mr-Akuma/8d84b564fb051caa1b1ea31b24f6b9fb - Exploit, Third Party Advisory | |
References | () https://moderncampus.com/products/web-content-management.html - Product, Vendor Advisory |
Information
Published : 2022-09-18 05:15
Updated : 2024-11-21 07:22
NVD link : CVE-2022-40766
Mitre link : CVE-2022-40766
CVE.ORG link : CVE-2022-40766
JSON object : View
Products Affected
moderncampus
- omni_cms
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')