Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: through 6.0. NOTE: The vendor was contacted and it was learned that the product is not supported.
INFO
Published Date :
2025-03-20T07:25:11.647Z
Last Modified :
2025-03-20T15:09:41.232Z
Source :
TR-CERT
AFFECTED PRODUCTS
The following products are affected by CVE-2024-12016 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-12016.
| URL | Resource |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-25-0072 |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact