CVE-2023-51052
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 21, 2023
Updated: Dec 29, 2023
CWE ID 89
Summary
CVE-2023-51052 is a newly disclosed SQL injection vulnerability affecting S-CMS version 5.0. Attackers can exploit this flaw by injecting malicious SQL code through the A_formauth parameter in the /admin/ajax.php endpoint. Successful exploitation could result in unauthorized access to sensitive data or even complete system takeover. Users are strongly advised to update their S-CMS installations to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.