PT-2022-27468 · Aerocms · Aerocms

CVE-2022-45329

·

Published

2022-11-29

·

Updated

2022-11-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AeroCMS version 0.0.1
Description The issue allows attackers to access database information via a SQL Injection vulnerability in the Search parameter.
Recommendations For AeroCMS version 0.0.1, avoid using the Search parameter until a fix is available. As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45329

Affected Products

Aerocms