CVE-2020-36972

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
28/01/2026
Last modified:
28/01/2026

Description

SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information.