Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds