Impact
CMSsite 1.0 permits unauthenticated attackers to inject SQL code through the "post" parameter in post.php. This flaw allows an attacker to alter database queries, extract sensitive information, or conduct time‑based blind SQL injection attacks, potentially compromising the confidentiality of the underlying data.
Affected Systems
The vulnerability affects VictorAlagwu CMSsite version 1.0. Users running this edition of the CMS are at risk unless updated.
Risk and Exploitability
The flaw is assigned a CVSS score of 8.8, indicating high severity, yet its EPSS score is below 1%, suggesting a low probability of exploitation in the wild. It is not listed in CISA’s KEV catalog. The likely method of exploitation involves sending a crafted GET request to post.php with malicious "post" values, with no authentication required.
OpenCVE Enrichment