An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20296
Reference (s):
- https://github.com/arterli/CmsWing/issues/51

