AeroCMS 0.1.1 contains a SQL injection caused by unsanitized author parameter, letting attackers execute arbitrary SQL commands, exploit requires crafted author input.
id: CVE-2022-38812
info:
name: AeroCMS 0.1.1 - SQL Injection
author: shivampand3y
severity: m
...