CVE-2026-73670: Saurus CMS Community Edition
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform table traversal, time-based blind, boolean-based blind, and error-based injection techniques to enumerate full database schema, access system tables such as information_schema, and chain the disclosure with secondary injection points to extract credential data.
Affected products
- Saurus Saurus CMS Community Edition: up to and including d886e5b
Published 2026-08-13. Last modified 2026-09-09.