In libadminactiondataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20975
Reference (s):
- https://blog.csdn.net/qq_41770175/article/details/93486383
Get a Pentest and security assessment of your IT network.
In libadminactiondataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20975
Reference (s):