CVE-2020-36972
SmartBlog 2.0.1 - 'id_post' Blind SQL injection
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information.
| CWE | CWE-89 |
| Vendor | smartdatasoft |
| Product | smartblog |
| Published | Jan 28, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for smartdatasoft smartblog
Be the first to know when new high vulnerabilities affecting smartdatasoft smartblog are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
smartdatasoft / SmartBlog
2.0.1
References
Credits
C0wnuts