Unrated severityNVD Advisory· Published Jan 28, 2026· Updated Mar 5, 2026
SmartBlog 2.0.1 - 'id_post' Blind SQL injection
CVE-2020-36972
Description
SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information.
Affected products
2- smartdatasoft/SmartBlogv5Range: 2.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.exploit-db.com/exploits/48995mitreexploit
- www.vulncheck.com/advisories/smartblog-idpost-blind-sql-injectionmitrethird-party-advisory
News mentions
0No linked articles in our index yet.