Loading vulnerability details…
CVSS v3.1
N/A
EPSS
4.06%
Published
Apr 24, 2017
Modified
May 12, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
Weaknesses (CWE)
Affected Products (1)
References (8)