VYPR
Medium severity5.5NVD Advisory· Published Dec 31, 2023· Updated Jun 17, 2026

CVE-2023-7190

CVE-2023-7190

Description

A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issue is some unknown functionality of the file /member/ad.php?action=ad. The manipulation of the argument A_text/A_url/A_contact leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

5
  • S CMS/S CMSllm-fuzzy4 versions
    <=2.0_build20220529-20231006+ 3 more
    • (no CPE)range: <=2.0_build20220529-20231006
    • cpe:2.3:a:s-cms:s-cms:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:s-cms:s-cms:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:s-cms:s-cms:2.0:build_20220529-20231006:*:*:*:*:*:*
  • Range: 2.0_build20220529-20231006

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.