CVE-2015-2070: Etouch Samepage

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed.

Affected products

  • Etouch Samepage: version 4.4.0.0.239 only

Published 2015-02-24. Last modified 2026-06-17.