A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/client/article/list. The manipulation of the argument orderBy leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/IceFoxH/VULN/issues/8 | Exploit Issue Tracking |
https://github.com/IceFoxH/VULN/issues/8 | Exploit Issue Tracking |
https://github.com/IceFoxH/VULN/issues/9 | Exploit Issue Tracking |
https://github.com/IceFoxH/VULN/issues/9 | Exploit Issue Tracking |
https://vuldb.com/?ctiid.300577 | Permissions Required VDB Entry |
https://vuldb.com/?id.300577 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.517926 | Third Party Advisory VDB Entry |
Configurations
History
01 Apr 2025, 20:23
Type | Values Removed | Values Added |
---|---|---|
First Time |
Xjd2020
Xjd2020 fastcms |
|
CPE | cpe:2.3:a:xjd2020:fastcms:*:*:*:*:*:*:*:* | |
References | () https://vuldb.com/?submit.517926 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?ctiid.300577 - Permissions Required, VDB Entry | |
References | () https://github.com/IceFoxH/VULN/issues/9 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?id.300577 - Third Party Advisory, VDB Entry | |
References | () https://github.com/IceFoxH/VULN/issues/8 - Exploit, Issue Tracking |
21 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
CWE | CWE-74 |
21 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-21 15:15
Updated : 2025-04-01 20:23
NVD link : CVE-2025-2593
Mitre link : CVE-2025-2593
JSON object : View
Products Affected
xjd2020
- fastcms
CWE
No CWE.