← Vulnerability feed

Vulnerability record · CVE-2017-5346 · published 12 January 2017

CVE-2017-5346: Genixcms sql injection vulnerability

GGenixcms · Genixcms

SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.

7.2 CVSS 3.0 High EPSS 1.6% · top 24.5% CWE-89 · SQL injection
7.2CVSS 3.0 base score, v2 6.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5346 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2017-8827Genixcms improper authentication vulnerabilityforgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibl…EPSS 1.6%8.8CVE-2017-14763Genixcms vulnerabilityIn the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.EPSS 1.4%8.8CVE-2017-14764Genixcms code injection vulnerabilityIn the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.EPSS 1.5%8.8CVE-2017-8377Genixcms sql injection vulnerabilityGeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.EPSS 1.5%7.5CVE-2015-2679Genixcms sql injection vulnerabilityMultiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page …EPSS 5.6%7.3CVE-2016-10096Genixcms sql injection vulnerabilitySQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation par…EPSS 1.6%6.1CVE-2017-17431Genixcms cross-site scripting vulnerabilityGeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-201…EPSS 0.68%6.1CVE-2017-14761Genixcms cross-site scripting vulnerabilityIn GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2017-5346), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.