Loading HuntDB...

GHSA-hgqj-74jh-w3vh

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The attack uses an admin/trees/add/process request with a crafted _tags[] parameter that is mishandled in a later admin/ajax/dashboard/approve-change request.

Related CVEs

Key Information

GHSA ID
GHSA-hgqj-74jh-w3vh
Published
May 17, 2022 12:17 AM
Last Modified
May 17, 2022 12:17 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.