CVE-2024-45265# CVE-2024-45265
## Suggested description
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3132 allows remote attackers to execute arbitrary SQL commands via the `psid` parameter.
## Vulnerability Type
CWE-89 | SQL Injection
## Vendor of Product
SkySystem (https://skyss.ru/)
## Affected Product Code Base
Arfa-CMS - 5.1.3124 and earlier
## Impact Escalation of Privileges
true
## Has vendor confirmed or acknowledged the vulnerability?
true
## Discoverer
Kirill Kalimmulin
## Reference
https://skyss.ru
[4.0K] /data/pocs/c1861602dfe16da1ea9a78652fc6cc26f2033613
└── [ 548] README.md
0 directories, 1 file