A SQL injection vulnerability in the 4.edu.phpconnfunction.php component of S-CMS v1.0 allows attackers to access sensitive database information.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20340
Reference (s):
- https://github.com/mntn0x/POC/blob/master/S-CMS/S-CMS-SQL%E6%B3%A8%E5%85%A5.md