CVE-2020-18877: SQL Injection
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-18877?
CVE-2020-18877 is a SQL Injection vulnerability in Wuzhi CMS v4.1.0.
How does CVE-2020-18877 impact the affected software?
CVE-2020-18877 allows remote attackers to obtain sensitive information by injecting malicious SQL queries through the 'flag' parameter in the component '/coreframe/app/order/admin/index.php' of Wuzhi CMS v4.1.0.
What is the severity of CVE-2020-18877?
CVE-2020-18877 has a severity rating of 7.5 (High).
How can I fix CVE-2020-18877?
To fix CVE-2020-18877, it is recommended to upgrade to a patched version of Wuzhi CMS that addresses the SQL Injection vulnerability.
Where can I find more information about CVE-2020-18877?
More information about CVE-2020-18877 can be found at the following reference: [https://github.com/wuzhicms/wuzhicms/issues/175]