CVE-2024-3816 is a critical blind SQL Injection vulnerability affecting Concept Intermedia's S@M CMS, allowing unauthenticated attackers to execute arbitrary SQL queries via the search bar. With a CVSS score of 9.8, this flaw poses a severe risk of complete compromise of confidentiality, integrity, and availability due to its network-based attack vector and low complexity. While the vendor has not fully investigated the root cause, there is currently no public exploit code, Metasploit modules, or evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3CPE matchmatch criteria | cpe:2.3:a:conceptintermedia:s\@m_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.