SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.
No PoCs from references.
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/thetrueartist/ABO.CMS-EXPLOIT-Unauthenticated-Login-Bypass-CVE-2024-25227
- https://github.com/thetrueartist/ABO.CMS-Login-SQLi-CVE-2024-25227