VDB
Sign up
CRITICAL

GHSA-mrmx-jfw8-qhgv

Melis Platform CMS SQL Injection

Quick fix

GHSA-mrmx-jfw8-qhgv — melisplatform/melis-cms: upgrade to the fixed version with the command below.

composer require melisplatform/melis-cms:^5.3.4

Details

SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/melisplatform/melis-cms
Introduced in: 0Fixed in: 5.3.4
Fixcomposer require melisplatform/melis-cms:^5.3.4

References