Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:smartdatasoft:smartblog:2.0.1:*:*:*:*:*:*:* |
Mon, 09 Feb 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:smartdatasoft:smartblog:2.0.1:*:*:*:*:prestashop:*:* |
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smartdatasoft
Smartdatasoft smartblog |
|
| Vendors & Products |
Smartdatasoft
Smartdatasoft smartblog |
Wed, 28 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information. | |
| Title | SmartBlog 2.0.1 - 'id_post' Blind SQL injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T01:27:14.502Z
Reserved: 2026-01-27T15:47:07.998Z
Link: CVE-2020-36972
Updated: 2026-01-28T18:58:25.635Z
Status : Analyzed
Published: 2026-01-28T18:16:47.840
Modified: 2026-02-09T17:57:31.140
Link: CVE-2020-36972
No data.
OpenCVE Enrichment
Updated: 2026-01-29T09:09:15Z