CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.
References
Link Resource
https://github.com/chshcms/cscms/issues/26#issue-1207651726 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-26T13:27:32

Updated: 2022-05-26T13:27:32

Reserved: 2022-04-25T00:00:00


Link: CVE-2022-29667

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-26T14:15:08.563

Modified: 2022-05-28T02:30:16.587


Link: CVE-2022-29667

JSON object: View

cve-icon Redhat Information

No data.

CWE