An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?mAdmin&cAd&acategory sort parameter.
Publication date: Wed, 16 Oct 2019 04:15:00 +0000