Junglewise Threat Intelligence

CVE-2017-5575: GeniXCMS SQL injection in Options.class.php

CVE-2017-5575 · Severity: critical · CVSS 9.8 · Published 2017-01-23

Technologies: Metalgenix Genixcms. Vendors: Metalgenix.

Executive brief

GeniXCMS, a content management system, is vulnerable to a critical security flaw that allows remote attackers to interfere with its database. By sending specially crafted requests, an attacker can view, modify, or delete sensitive information stored in the system's database without needing a password. This could lead to a total compromise of the website, including the theft of user data or the disruption of services.

Technical details

A SQL injection vulnerability exists in GeniXCMS versions prior to 1.0.0 within the 'inc/lib/Options.class.php' component. The vulnerability is caused by improper neutralization of special elements used in SQL commands, specifically affecting the 'modules' parameter. A remote, unauthenticated attacker can exploit this by sending a malicious network request to execute arbitrary SQL commands against the underlying database. This can result in full unauthorized access to data, modification of database records, or administrative bypass. The issue was addressed in the v1.0.0 release.

Affected products

  • GeniXCMS GeniXCMS before 1.0.0

Timeline

  • 2017-01-22: patched: GeniXCMS v1.0.0 released fixing the issue.
  • 2017-01-23: advisory: NVD published the CVE record.

References

Related threats