CVE-2018-17852: SQL Injection
Published Oct 1, 2018
·Updated
A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detaillisting URI.
Affected Software
1 affected component
Wuzhi Cms Project Wuzhi Cms=4.1.0
Event History
Oct 1, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17852?
CVE-2018-17852 is classified as a moderate severity SQL injection vulnerability.
2
How do I fix CVE-2018-17852?
To fix CVE-2018-17852, it is recommended to validate and sanitize the 'groupname' parameter input in the affected WUZHI CMS version.
3
What software is affected by CVE-2018-17852?
CVE-2018-17852 affects WUZHI CMS version 4.1.0.
4
What type of vulnerability is CVE-2018-17852?
CVE-2018-17852 is a SQL injection vulnerability found in WUZHI CMS.
5
Where is CVE-2018-17852 exploited in the application?
CVE-2018-17852 can be exploited through the /index.php?m=coupon&f=card&v=detail_listing URI using the groupname parameter.