A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19821
Reference (s):
- https://github.com/millken/doyocms/issues/3

