Impact
The vulnerability is an unauthenticated SQL injection in Listing Hub CMS 1.0, where the id parameter of pages.php is not validated. Attackers can send crafted GET requests using error‑based techniques to execute arbitrary SQL statements. This allows extraction of sensitive data such as database usernames, passwords, and version information, essentially compromising the integrity and confidentiality of the underlying database.
Affected Systems
Only the 1.0 release of Listing Hub CMS from Themerig is known to contain this flaw. No other versions or related products are listed; the vendor’s advisory specifically cites version 1.0. Therefore systems running this version of the CMS are impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and although the EPSS score is not available, the nature of the vulnerability suggests a readily exploitable attack path via an HTTP GET request. The flaw is not cataloged in the CISA KEV list, but it remains a significant risk because it can be triggered remotely without authentication. Following the vendor’s recommendation to apply a patch or upgrade is essential to eliminate this risk.
OpenCVE Enrichment