DDSN Interactive cm3 Acora CMS Time-Based Blind SQL Injection Vulnerability

Vulnerability

A time-based blind SQL injection vulnerability has been identified in DDSN Interactive cm3 Acora CMS version 10.1.1. This vulnerability arises from inadequate input sanitization and validation in the 'table' parameter, allowing attackers to inject malicious SQL queries. The exploitation of this vulnerability could lead to unauthorized access, data manipulation, or exposure of sensitive information, significantly compromising the application's integrity and confidentiality.

Impact

Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can execute arbitrary SQL commands that could manipulate the database or extract sensitive information.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
8.3
remediation
0.0
relevance
0.0
threat
0.3
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.