CVEs Blog | G5 Cyber Security

CVE-2020-20295 – An issue was found in CMSWing project version 1.3.8. Because the updateAc

An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20295

Reference (s):

Exit mobile version