CVE-2022-29660
Description
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection vulnerability in CSCMS Music Portal System v4.2 allows authenticated admin users to execute arbitrary SQL via the id parameter in the image deletion endpoint.
Vulnerability
CSCMS Music Portal System v4.2 contains a SQL injection vulnerability in the pic_Pic.php_del file, reachable through the admin panel at /admin.php/pic/admin/pic/del. The id parameter is not sanitized before being used in a database query, allowing injection of arbitrary SQL. The vulnerability requires an authenticated admin session to access the endpoint [1].
Exploitation
An attacker with valid admin credentials can craft a POST request to /admin.php/pic/admin/pic/del with a malicious id parameter. The proof-of-concept in the reference shows a time-based blind SQL injection using id=1)and(sleep(5))--+, which causes a 5-second delay if the injection succeeds. The attacker can then systematically extract database content by observing response times [1].
Impact
Successful exploitation enables an attacker to exfiltrate sensitive data from the database, such as admin credentials or configuration secrets. The impact is limited to information disclosure via blind SQL injection; remote code execution is not demonstrated in the available reference [1].
Mitigation
No official patch has been released by the vendor as of the publication date. The only mitigation is to restrict admin panel access to trusted users and apply input validation on the id parameter through a web application firewall or custom code changes. The issue remains open in the vendor's repository [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- CSCMS/Music Portal Systemdescription
- Range: <4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/chshcms/cscms/issues/25mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.