HIGH7.2
GHSA-2ppw-6xvg-rwgw
GeniXCMS SQL injection vulnerability
Quick fix
GHSA-2ppw-6xvg-rwgw — genix/cms: upgrade to the fixed version with the command below.
composer require genix/cms:^1.0.0Details
SQL injection vulnerability in `inc/lib/Control/Backend/posts.control.php` in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-5346[ADVISORY]
- https://github.com/semplon/GeniXCMS/issues/61[WEB]
- https://github.com/semplon/GeniXCMS/commit/abfbb6103bfa860275f89d1215ed9c3cba94791e[WEB]
- https://github.com/GeniXCMS/GeniXCMS[PACKAGE]
- http://code610.blogspot.com/2017/01/genixcms-sql-injection-quick-autopsy.html[WEB]
- http://www.securityfocus.com/bid/95655[WEB]