CVEs Blog | G5 Cyber Security

CVE-2020-18877 – SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensi

SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the ‘flag’ parameter in the component ‘/coreframe/app/order/admin/index.php’.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18877

Reference (s):

Exit mobile version