CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Cszcms
Cszcms cszcms
Vendors & Products Cszcms
Cszcms cszcms

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
Description CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.
Title CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-11T21:41:54.372Z

Reserved: 2025-12-11T11:49:20.718Z

Link: CVE-2024-58307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-12-11T22:15:52.173

Modified: 2025-12-12T15:17:31.973

Link: CVE-2024-58307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-12T08:48:38Z

Weaknesses