Back

HIGH

S-CMS reg.php sql injection

Published Dec 31, 2023

Description

A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown part of the file member/reg.php. The manipulation of the argument M_login/M_email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249393 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 31, 2023
Updated Apr 17, 2025
Reserved Dec 30, 2023
CISA Vulnrichment
Updated Jan 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulDB
Published Dec 31, 2023
Updated Apr 17, 2025
Exploited since n/a
EUVD-2023-59372