CVE-2024-36801
MEDIUM 5.9EPSS 0.4%
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.
- CVSS v3.1
- 5.9 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - EPSS
- 0.39% chance of exploitation in the next 30 days, 32th percentile
- Published
- 2024-06-04
- Updated
- 2025-02-13