← Terug naar overzicht

A SQL injection vulnerability has been identified in the light0011 CMS project at specific commits. The flaw resides in the ChapterModel::searchChapter function within App/Home/Controller/ChapterController.class.php, where the 'content' argument is not properly sanitized by the Query Builder component. Remote attackers can exploit this vulnerability without authentication. A public exploit has been released, increasing the risk of active exploitation. The product does not follow versioning, making it impossible to identify affected or unaffected releases. The project maintainer was notified via a GitHub issue but has not responded. This vulnerability poses a significant risk to any deployments of this CMS.

Affected products

  • light0011 CMS

Related CVE's

  • CVE-2026-85379

Categories

  • Database & Storage
  • Web Technologies
  • Zero-Day Vulnerabilities