HIGH7.3
GHSA-gjcj-fj23-5j5v
GeniXCMS SQL injection vulnerability
Quick fix
GHSA-gjcj-fj23-5j5v — genix/cms: upgrade to the fixed version with the command below.
composer require genix/cms:^1.0.0Details
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-10096[ADVISORY]
- https://github.com/semplon/GeniXCMS/issues/58[WEB]
- https://github.com/semplon/GeniXCMS/commit/d885eb20006099262c0278932b9f8aca3c1ac97f[WEB]
- https://github.com/GeniXCMS/GeniXCMS[PACKAGE]
- http://www.hackersb.cn/shenji/107.html[WEB]
- http://www.securityfocus.com/bid/95172[WEB]