Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.

Project Subscriptions

Vendors Products
Aerocms Project Subscribe
Aerocms Subscribe
Megatkc Subscribe
Aero Cms Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Feb 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Aerocms Project
Aerocms Project aerocms
CPEs cpe:2.3:a:aerocms_project:aerocms:0.0.1:*:*:*:*:*:*:*
Vendors & Products Aerocms Project
Aerocms Project aerocms

Wed, 14 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Megatkc
Megatkc aero Cms
Vendors & Products Megatkc
Megatkc aero Cms

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.
Title Aero CMS 0.0.1 - SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-14T19:21:11.191Z

Reserved: 2026-01-10T15:05:18.988Z

Link: CVE-2022-50895

cve-icon Vulnrichment

Updated: 2026-01-14T15:53:23.826Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-13T23:15:51.293

Modified: 2026-02-27T19:47:07.920

Link: CVE-2022-50895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-14T11:08:41Z

Weaknesses