GHSA-3v3x-mvj6-m5jcCriticalCVSS 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Published
March 20, 2025
Last Modified
June 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0.

NOTE: The vendor was contacted and it was learned that the product is not supported.

🔗 References (4)