Concept Intermedia GOV CMS Blind SQL Injection Vulnerability

Vulnerability

A blind SQL injection vulnerability has been identified in Concept Intermedia GOV CMS versions prior to 4.0. The issue arises because the 'search' query parameter is not properly sanitized, allowing unauthenticated remote attackers to inject arbitrary SQL code.

Impact

Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries and potentially access or modify database information.

Added: Sep 4, 2025, 1:19 PM
Updated: Sep 4, 2025, 4:55 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.