
🚨 CRITICAL - Unauthenticated SQL Injection in Redeight CMS admin login (CVE-2026-53690) Redeight CMS 1.0 is vulnerable to SQL injection in the POST /admin/index.php login endpoint via the userEmail parameter, allowing hostile input to reach the database layer. The root cause is improper input validation and unsafe SQL query construction (string interpolation without prepared statements). An unauthenticated remote attacker can exploit this over the network by sending crafted POST requests to manipulate backend SQL execution during authentication. Successful exploitation can expose sensitive database contents and potentially enable broader compromise through credential disclosure and database tampering. 👉 Affected: Redeight CMS 1.0 | Upgrade to No fix yet — treat as suspicious
Post summary
Redeight CMS 1.0 is vulnerable to unauthenticated SQL injection in the admin login endpoint; detailed technical information is provided, but no PoC, exploit, patch, or evidence of active exploitation is present.


