Critical severity9.8NVD Advisory· Published Nov 8, 2017· Updated May 13, 2026
CVE-2015-3933
CVE-2015-3933
Description
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
genix/cmsPackagist | <= 0.0.3 | — |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/semplon/GeniXCMS/releases/tag/v0.0.3-patchnvdPatchWEB
- github.com/advisories/GHSA-q4hw-62mx-q37wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-3933ghsaADVISORY
- www.exploit-db.com/exploits/37363/nvdThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/37363ghsaWEB
News mentions
0No linked articles in our index yet.