High severity8.8NVD Advisory· Published Feb 3, 2022· Updated Jun 17, 2026
CVE-2022-23873
CVE-2022-23873
Description
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
Affected products
3- cpe:2.3:a:victor_cms_project:victor_cms:1.0:*:*:*:*:*:*:*
- Victor/CMSdescription
- Range: 1.0
Patches
Vulnerability mechanics
References
1- github.com/truonghuuphuc/CVE/blob/main/CVE-2022-23873.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.