First published: Thu Apr 05 2018(Updated: )
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZCMS | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9309 has a medium CVSS score, indicating a moderate impact potential due to SQL injection.
To fix CVE-2018-9309, validate and sanitize the 'id' parameter in the dl/dl_sendsms.php request to prevent SQL injection.
CVE-2018-9309 affects zzcms version 8.2 specifically.
CVE-2018-9309 is classified as an SQL injection vulnerability.
Yes, CVE-2018-9309 can be exploited remotely through crafted HTTP requests targeting the vulnerable script.