First published: Thu Feb 04 2021(Updated: )
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZZZCMS zzzphp | =1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-18717 is a SQL Injection vulnerability in ZZZCMS zzzphp 1.7.1 that allows remote attackers to execute arbitrary code.
CVE-2020-18717 has a severity rating of 9.8 (Critical).
CVE-2020-18717 is caused by a lack of parameter filtering in the 'inc/zzz_template.php' file, which allows remote attackers to exploit a SQL Injection vulnerability and execute arbitrary code.
Yes, to fix CVE-2020-18717, update ZZZCMS zzzphp to a version that includes a fix for the SQL Injection vulnerability.
More information about CVE-2020-18717 can be found at the following link: [https://www.seebug.org/vuldb/ssvid-98031](https://www.seebug.org/vuldb/ssvid-98031)