CVE-2018-14472: SQL Injection
Published Jul 20, 2018
·Updated
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Jul 20, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-14472.
2
What is the severity of CVE-2018-14472?
The severity of CVE-2018-14472 is high with a CVSS score of 7.2.
3
What is the affected software of CVE-2018-14472?
The affected software of CVE-2018-14472 is Wuzhicms 4.1.0.
4
What is the CWE of CVE-2018-14472?
The CWE of CVE-2018-14472 is CWE-89 (SQL Injection).
5
How can I fix CVE-2018-14472?
To fix CVE-2018-14472, apply the relevant patches or updates provided by Wuzhicms.