No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious SQL code in the order_by[0] parameter to extract sensitive database information.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious SQL code in the order_by[0] parameter to extract sensitive database information. | |
| Title | No-Cms 1.0 SQL Injection via order_by Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-01T21:00:21.652Z
Reserved: 2026-06-01T11:48:19.971Z
Link: CVE-2018-25431
No data.
Status : Received
Published: 2026-06-01T22:16:16.440
Modified: 2026-06-01T22:16:16.440
Link: CVE-2018-25431
No data.
OpenCVE Enrichment
Updated: 2026-06-01T22:30:03Z