CVE-2024-25227
CRITICAL 9.8EPSS 0.8%
SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 0.79% chance of exploitation in the next 30 days, 54th percentile
- Published
- 2024-03-15
- Updated
- 2025-03-26
Proof-of-concept exploits (2)
- thetrueartist/ABO.CMS-EXPLOIT-Unauthenticated-Login-Bypass-CVE-2024-252270★ · 2024-03-22
- thetrueartist/ABO.CMS-Login-SQLi-CVE-2024-252270★ · 2024-03-13