Back to search
CVE-2024-58301
Published: Dec 11, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.
| Vendor | Product | Versions |
|---|---|---|
purei | Purei CMS | affected 1.0 |
Weaknesses (CWE)
References
ExploitDB-51929
exploit
Purei Homepage
product
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now