Impact
A flaw in SSCMS 7.4.0 allows attackers to inject arbitrary SQL code through the tableHandWrite parameter in SitesAddController.Submit.cs, exploiting CWE‑89 and CWE‑74 weaknesses. If this vulnerability is triggered, the attacker can read, modify or delete data from the database, compromising the confidentiality, integrity, and possibly the availability of the application.
Affected Systems
The vulnerability impacts the SSCMS web content management system, specifically the DDL Handler component in the SitesAddController.Submit.cs file. Only the 7.4.0 release is known to be affected; newer or older versions may not be vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in normal circumstances. The flaw is exploitable remotely and has already been released to the public, so an attacker could target any exposed instance. The vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation to date.
OpenCVE Enrichment