CVE-2015-7568: Yeager CMS
Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
Affected products
- Yeager Yeager CMS: version 1.2.1 only
Published 2017-04-24. Last modified 2026-06-17.