PT-2026-71691 · Saurus · Saurus Cms Community Edition

·

CVE-2026-73670

·

Published

2026-08-13

·

Updated

2026-08-14

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A CMS contains a SQL injection flaw in the 'admin/db data.php' endpoint. Authenticated administrators can inject arbitrary SQL into a SHOW COLUMNS FROM statement by providing unsanitized input via the table name GET or POST parameter. This allows for table traversal, time-based blind, boolean-based blind, and error-based injection techniques to enumerate the full database schema and access system tables such as information schema. This disclosure can be chained with secondary injection points to extract credential data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the table name parameter in the 'admin/db data.php' endpoint until the issue is resolved.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73670

Affected Products

Saurus Cms Community Edition