WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00079}

epss

{'score': 0.00089}


Tue, 29 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Wtcms Project
Wtcms Project wtcms
Weaknesses CWE-89
CPEs cpe:2.3:a:wtcms_project:wtcms:1.0:*:*:*:*:*:*:*
Vendors & Products Wtcms Project
Wtcms Project wtcms
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Oct 2024 21:45:00 +0000

Type Values Removed Values Added
Description WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-29T18:53:50.682Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48238

cve-icon Vulnrichment

Updated: 2024-10-29T18:53:26.187Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T22:15:02.713

Modified: 2025-04-17T18:59:35.273

Link: CVE-2024-48238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.