Description
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data action, which receives an input from user and passes it unsanitized to the core model `filterFunc` function that further embeds this data in an SQL statement. This allows attackers to inject unwanted SQL code into the statement. The `period` should be escaped before inserting it in the query. As of time of publication, a patched version is not available.
Published: 2024-04-04
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-29112 InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data action, which receives an input from user and passes it unsanitized to the core model `filterFunc` function that further embeds this data in an SQL statement. This allows attackers to inject unwanted SQL code into the statement. The `period` should be escaped before inserting it in the query. As of time of publication, a patched version is not available.
History

Fri, 17 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Instantcms instantcms
CPEs cpe:2.3:a:instantcms:instantcms:2.16.2:*:*:*:*:*:*:*
Vendors & Products Instantcms instantcms

Subscriptions

Instantcms Icms2 Instantcms
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:46:04.773Z

Reserved: 2024-03-29T14:16:31.900Z

Link: CVE-2024-31212

cve-icon Vulnrichment

Updated: 2024-07-16T00:02:11.313Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-04T23:15:16.540

Modified: 2025-01-17T14:58:34.137

Link: CVE-2024-31212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses