CVE-2018-11722: SQL Injection
Published Jun 5, 2018
·Updated
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UCKEY' is hard coded.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Jun 5, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11722?
CVE-2018-11722 is a SQL Injection vulnerability in WUZHI CMS 4.1.0.
2
How does the SQL Injection vulnerability occur in WUZHI CMS 4.1.0?
The SQL Injection vulnerability in WUZHI CMS 4.1.0 occurs in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
3
What is the severity of CVE-2018-11722?
The severity of CVE-2018-11722 is critical with a severity value of 9.8.
4
How can I fix the SQL Injection vulnerability in WUZHI CMS 4.1.0?
To fix the SQL Injection vulnerability in WUZHI CMS 4.1.0, update to a version that has patched this vulnerability.
5
Where can I find more information about CVE-2018-11722?
More information about CVE-2018-11722 can be found at the following reference: https://github.com/wuzhicms/wuzhicms/issues/141