First published: Fri Jun 17 2022(Updated: )
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-12358.
The severity of CVE-2019-12358 is high with a score of 8.8.
The affected software is Zzcms 2019.
An attacker can exploit this vulnerability by injecting malicious SQL statements via the dlid cookie in the /dl/dl_sendsms.php page, when having dls_print authority.
Yes, it is recommended to update to a patched version of Zzcms 2019 to fix this vulnerability.