Description
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 5.3.4
Credits
Jesús Manzano Vázquez
Juan Manuel Martínez Hernández
Manuel Iván San Martín Castillo
Ángel Montilla Muñoz
References
www.incibe.es/...iso/multiple-vulnerabilities-melis-platform