CVE-2020-15333: SQL Injection
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select from Administratorusers" and "select from Usersusers" requests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15333?
CVE-2020-15333 is a vulnerability in Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 that allows attackers to discover accounts via MySQL select * from Administrator_users and select * from Users_users requests.
How severe is CVE-2020-15333?
CVE-2020-15333 has a severity score of 5.3 (Medium).
Which software versions are affected by CVE-2020-15333?
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 are affected by CVE-2020-15333.
How can attackers exploit CVE-2020-15333?
Attackers can exploit CVE-2020-15333 by sending MySQL select * from Administrator_users and select * from Users_users requests to discover accounts.
Are there any references for CVE-2020-15333?
Yes, you can find more information about CVE-2020-15333 at the following references: [Reference 1](https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html) and [Reference 2](https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml).