First published: Wed Dec 26 2018(Updated: )
An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =3.0 | |
=3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20477 is an SQL Injection vulnerability in S-CMS 3.0, specifically in the bank/callback1.php P_no field.
CVE-2018-20477 has a severity score of 9.8, which is classified as critical.
CVE-2018-20477 allows attackers to perform SQL Injection attacks in S-CMS 3.0 through the bank/callback1.php P_no field.
To fix CVE-2018-20477, it is recommended to update S-CMS to the latest version or apply a patch provided by the vendor.
CWE-89 is a category of vulnerability known as SQL Injection, which allows attackers to manipulate SQL queries to extract, modify, or delete data in a database.