Description

Multiple vulnerabilities exist in RuubikCMS version 1.0.3, including cross-site scripting and SQL injection flaws. User input is insufficiently sanitized across multiple parameters.

Impact

Attackers can execute arbitrary JavaScript in the context of other users' browsers (XSS) and manipulate database queries to extract or modify data (SQL injection). This can lead to complete compromise of the CMS.

Solution

Upgrade to the latest version of RuubikCMS or apply available security patches.

References