Back

CVE-2018-18619

CRITICAL

internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued.

Published: Nov 29, 2018 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
advanced_comment_system_project advanced_comment_system 1.0

GitHub Security Advisory GHSA-wcm8-xfhp-fcf8

internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL...

References (6)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.19%

Top 10% most likely to be exploited

Threat Score 40.5 / 100

Data Sources

NVD EPSS GitHub