CVE-2023-0244

A vulnerability classified as critical was found in TuziCMS 2.0.6. This vulnerability affects the function delall of the file \App\Manage\Controller\KefuController.class.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218152.
References
Link Resource
https://github.com/yeyinshi/tuzicms/issues/13 Exploit Third Party Advisory
https://vuldb.com/?ctiid.218152 Permissions Required Third Party Advisory
https://vuldb.com/?id.218152 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tuzicms_project:tuzicms:2.0.6:*:*:*:*:*:*:*

History

11 Apr 2024, 01:17

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad crítica TuziCMS 2.0.6. Esta vulnerabilidad afecta la función delall del archivo \App\Manage\Controller\KefuController.class.php. La manipulación del argumento id conduce a la inyección de SQL. El ataque se puede iniciar de forma remota.La explotación ha sido divulgada al público y puede utilizarse. El identificador de esta vulnerabilidad es VDB-218152.

Information

Published : 2023-01-12 15:15

Updated : 2024-05-17 02:17


NVD link : CVE-2023-0244

Mitre link : CVE-2023-0244

CVE.ORG link : CVE-2023-0244


JSON object : View

Products Affected

tuzicms_project

  • tuzicms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')