CVE-2023-39805
Critical · CVSS 9.8iCMS — SQL Injection
- CVSS
- 9.8
- nvd
- EPSS
- 0.59%
- 44th pct
- KEV
- No
- Class
- other
- CWE-89
Description
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
Search profile — drives PoC discovery
Symbols admincp.phpwhereiCMSSQL injectionwhere parameter
Keywords CVE-2023-39805iCMSiCMS v7.0.16SQL injectionadmincp.phpwhere parametericmsdevCWE-89
Versions: 7.0.16
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z