{"id":"GHSA-qrw3-mq8r-cq7q","summary":"AdaptCMS SQL Injection vulnerability","details":"SQL injection vulnerability in the \"Check User\" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.","aliases":["CVE-2008-4524"],"modified":"2025-04-10T01:57:08.364669Z","published":"2022-05-02T00:10:55Z","database_specific":{"nvd_published_at":"2008-10-09T18:14:00Z","cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-04-10T01:10:23Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4524"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45642"},{"type":"PACKAGE","url":"https://github.com/adaptcms/AdaptCMS"},{"type":"WEB","url":"https://web.archive.org/web/20200228141415/http://www.securityfocus.com/bid/31557"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/6662"},{"type":"WEB","url":"http://www.adaptcms.com/article/51/News/URGENT-AdaptCMS-13-Security-Fix-Released"}],"affected":[{"package":{"name":"adaptcms/adaptcms","ecosystem":"Packagist","purl":"pkg:composer/adaptcms/adaptcms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qrw3-mq8r-cq7q/GHSA-qrw3-mq8r-cq7q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}