GHSA-3v3x-mvj6-m5jcCriticalCVSS 9.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
🔗 CVE IDs covered (1)
📋 Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0.
NOTE: The vendor was contacted and it was learned that the product is not supported.