First published: Thu Aug 26 2021(Updated: )
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2018 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19822 is a remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018.
CVE-2020-19822 can be exploited by attackers using the "ml" and "title" parameters to execute arbitrary PHP code.
CVE-2020-19822 has a severity rating of 7.2, which is considered high.
The CWE ID for CVE-2020-19822 is 94.
To fix CVE-2020-19822, update to a version of ZZCMS later than 2018 that contains a patch for the vulnerability.