VDB
Sign up
HIGH7.2

GHSA-2ppw-6xvg-rwgw

GeniXCMS SQL injection vulnerability

Quick fix

GHSA-2ppw-6xvg-rwgw — genix/cms: upgrade to the fixed version with the command below.

composer require genix/cms:^1.0.0

Details

SQL injection vulnerability in `inc/lib/Control/Backend/posts.control.php` in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms
Introduced in: 0Fixed in: 1.0.0
Fixcomposer require genix/cms:^1.0.0

References