Unrated severityNVD Advisory· Published Feb 24, 2012· Updated Jun 16, 2026
CVE-2012-0999
CVE-2012-0999
Description
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:lepton-cms:lepton:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:lepton-cms:lepton:*:*:*:*:*:*:*:*range: <=1.1.3
- cpe:2.3:a:lepton-cms:lepton:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:lepton-cms:lepton:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:lepton-cms:lepton:1.1.2:*:*:*:*:*:*:*
- (no CPE)range: <1.1.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.