CVE-2017-5347: Metalgenix Genixcms
High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.
Affected products
- Metalgenix Genixcms: version 0.0.8 only
Published 2017-01-12. Last modified 2026-06-17.