


Perceptive Security
SOC/SIEM Consultancy

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated…
Published:
2 februari 2026 om 23:00:00
Alert date:
3 februari 2026 om 19:04:17
Source:
nvd.nist.gov
Web Technologies, Database & Storage
CVE-2020-37110 affects 60CycleCMS version 2.5.2 with an SQL injection vulnerability in news.php and common/lib.php files. The vulnerability allows attackers to manipulate database queries through unvalidated user input, specifically through the 'title' parameter. Successful exploitation enables attackers to inject malicious SQL code and potentially extract or modify database contents. This is a database manipulation vulnerability that does not involve cross-site scripting. The vulnerability has exploit code publicly available and poses significant risk to affected CMS installations.
Technical details
Mitigation steps:
Affected products:
60CycleCMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2020-37110
https://www.exploit-db.com/exploits/48177
https://www.opensourcecms.com/60cyclecms
https://www.vulncheck.com/advisories/cyclecms-newsphp-sql-injection-vulnerability
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
