First published: Mon Oct 29 2018(Updated: )
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | =8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18792 is classified as a high severity vulnerability due to its potential to allow SQL injection attacks.
To fix CVE-2018-18792, you should validate and sanitize user inputs, particularly the pxzs cookie, and update to a secure version of the software.
CVE-2018-18792 specifically affects ZZCMS version 8.3.
Yes, exploitation of CVE-2018-18792 through SQL injection can lead to unauthorized access to sensitive data.
While there may not be a specific public exploit, the nature of SQL injection vulnerabilities generally allows for various methods of exploitation.