CVE-2024-12016
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: iletisim@usom.gov.tr (Secondary)
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.
This issue affects CM News: through 6.0.
NOTE: The vendor was contacted and it was learned that the product is not supported.
References (2)
Source: iletisim@usom.gov.tr
Source: iletisim@usom.gov.tr
Timeline
No history available yet.