Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.
📦
content_management_system
Vendor: cusg
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
3
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
0.73%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.5
CVSS
CVE-2023-48987
RCE
Severity: HIGH
6.1
CVSS
CVE-2023-48986
RCE
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.
Severity: MEDIUM
6.1
CVSS
CVE-2023-48985
RCE
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.
Severity: MEDIUM