First published: Wed Oct 17 2018(Updated: )
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18427 is a vulnerability that allows SQL Injection in s-cms 3.0 via the member/post.php 0_id parameter or the POST data to member/member_login.php.
CVE-2018-18427 has a severity rating of 9.8, which is considered critical.
CVE-2018-18427 affects s-cms 3.0.
To fix CVE-2018-18427, update to a version of s-cms that is not affected by this vulnerability.
You can find more information about CVE-2018-18427 at the following links: http://www.ttk7.cn/post-92.html, https://www.s-cms.cn/update.html