SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php’s getdata function.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18714
Reference (s):
- https://www.seebug.org/vuldb/ssvid-97858