CVE-2018-20572: SQL Injection
Published Dec 28, 2018
·Updated
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Dec 28, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20572?
CVE-2018-20572 is a vulnerability in WUZHI CMS 4.1.0 that allows SQL injection via the index.php?m=promote&f=index&v=search keywords parameter.
2
How severe is CVE-2018-20572?
CVE-2018-20572 has a severity rating of 9.8 (Critical).
3
What software version is affected by CVE-2018-20572?
WUZHI CMS version 4.1.0 is affected by CVE-2018-20572.
4
How can I fix CVE-2018-20572?
To fix CVE-2018-20572, update WUZHI CMS to a version that addresses the vulnerability.
5
Where can I find more information about CVE-2018-20572?
You can find more information about CVE-2018-20572 at the following link: [https://github.com/wuzhicms/wuzhicms/issues/166](https://github.com/wuzhicms/wuzhicms/issues/166)