SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSiberiancms
APPSiberiancms4.0.0 – 4.20.44 (excl.)5.0.0 – 5.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2024-41702CRITICAL9.8PL ✓same product
SQL Injection w SiberianCMS — krytyczna podatność bazy danych
CVE-2023-39375HIGH7.5same product
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
CVE-2023-39377HIGH7.2same product
SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative...
CVE-2025-1105MEDIUM5.3same product
A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is s...
CVE-2023-39376MEDIUM6.5same product
SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network...