First published: Mon Oct 29 2018(Updated: )
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | =8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18788 is considered a high severity vulnerability due to the potential for SQL Injection.
To fix CVE-2018-18788, update zzcms to the latest version that addresses this SQL Injection vulnerability.
Exploiting CVE-2018-18788 can allow an attacker to execute arbitrary SQL queries, potentially compromising the database.
Yes, CVE-2018-18788 requires an admin user login to exploit the SQL Injection vulnerability.
CVE-2018-18788 affects zzcms version 8.3.