CVE-2019-11518: SQL Injection
Published Apr 25, 2019
·Updated
An issue was discovered in SEMCMS 3.8. SEMCMSInquiry.php allows AID[] SQL Injection because the class.phpmailer.php injectchecksql protection mechanism is incomplete.
Affected Software
1 affected component
Sem-cms Semcms=3.8
Event History
Apr 25, 2019
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-11518.
2
What is the severity of CVE-2019-11518?
The severity of CVE-2019-11518 is high with a CVSS score of 7.2.
3
How does CVE-2019-11518 affect SEMCMS?
CVE-2019-11518 affects SEMCMS version 3.8.
4
How does the vulnerability CVE-2019-11518 manifest?
CVE-2019-11518 manifests as a SQL Injection vulnerability in SEMCMS_Inquiry.php due to incomplete protection mechanism.
5
Is there a fix available for CVE-2019-11518?
Unfortunately, there is no known fix available for CVE-2019-11518 at the moment.