


Perceptive Security
SOC/SIEM Consultancy

No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to mani…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 23:04:16
Source:
nvd.nist.gov
Web Technologies, Database & Storage
No-CMS version 1.0 contains a SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint. The vulnerability allows authenticated attackers to manipulate database queries by submitting malicious POST requests to the /nocms/main/manage_privilege/index/export endpoint. Attackers can exploit the order_by[0] parameter to inject malicious SQL code and extract sensitive database information. This vulnerability affects the privilege management functionality of the No-CMS content management system and requires authentication to exploit.
Technical details
Mitigation steps:
Affected products:
No-CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25431
https://codeload.github.com/goFrendiAsgard/No-CMS/zip/master
https://github.com/goFrendiAsgard/No-CMS
https://www.exploit-db.com/exploits/45903
https://www.vulncheck.com/advisories/no-cms-sql-injection-via-order-by-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
