thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19705
Reference (s):
- https://github.com/jorycn/thinkphp-zcms/issues/2
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19705
Reference (s):