top of page
perceptive_background_267k.jpg

60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through unvalidated…

Published:

2 februari 2026 om 23:00:00

Alert date:

3 februari 2026 om 19:04:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

CVE-2020-37110 affects 60CycleCMS version 2.5.2 with an SQL injection vulnerability in news.php and common/lib.php files. The vulnerability allows attackers to manipulate database queries through unvalidated user input, specifically through the 'title' parameter. Successful exploitation enables attackers to inject malicious SQL code and potentially extract or modify database contents. This is a database manipulation vulnerability that does not involve cross-site scripting. The vulnerability has exploit code publicly available and poses significant risk to affected CMS installations.

Technical details

Mitigation steps:

Affected products:

60CycleCMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page