First published: Thu Mar 07 2019(Updated: )
zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17415 is a SQL injection vulnerability in zzcms V8.3.
CVE-2018-17415 affects zzcms V8.3 through the /user/zs_elite.php file's id parameter.
CVE-2018-17415 has a severity rating of 8.8 (high).
To fix CVE-2018-17415, you should update zzcms to a version that includes a patch for this vulnerability.
More information about CVE-2018-17415 can be found at the following link: [CVE-2018-17415](https://github.com/seedis/zzcms/blob/master/SQL%20injection%20in%20zs_elite.php.md)