VYPR
Unrated severityNVD Advisory· Published May 26, 2022· Updated Aug 3, 2024

CVE-2022-29661

CVE-2022-29661

Description

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSCMS Music Portal System v4.2 contains a blind SQL injection vulnerability in the album delete function via the id parameter.

Vulnerability

CSCMS Music Portal System v4.2 is vulnerable to a blind SQL injection in the /admin.php/pic/admin/type/del endpoint. By manipulating the id parameter in a POST request when deleting an album from the recycle bin, an authenticated administrator can inject malicious SQL statements. The issue is present in the pic_Type.php_del function and affects version 4.2 [1].

Exploitation

To exploit this vulnerability, an attacker must first log in with valid administrator credentials. After creating an album, the attacker sends a POST request to /admin.php/pic/admin/type/del with a crafted id parameter, such as id=4)and(sleep(5))--+. The payload results in a 5-second database delay, confirming the blind SQL injection [1].

Impact

A successful blind SQL injection allows the attacker to extract the entire database schema, including sensitive data such as usernames and passwords. The attacker can use timing-based techniques to retrieve information byte by byte. The vulnerability is limited to authenticated administrators but exposes the database to full compromise [1].

Mitigation

The vendor has not released a patched version as of the publication date (2022-05-26). Administrators should restrict access to the admin panel, monitor for suspicious POST requests to /admin.php/pic/admin/type/del, and consider applying input validation or a web application firewall as a temporary workaround until an official fix is available [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.