First published: Thu Oct 14 2021(Updated: )
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19957 is a SQL injection vulnerability in zz cms version 2019 that allows attackers to retrieve sensitive data.
An attacker can exploit the CVE-2020-19957 vulnerability by using the id parameter on the /dl/dl_print.php page to inject malicious SQL queries.
The severity of CVE-2020-19957 is high with a CVSS score of 7.5.
CVE-2020-19957 affects zz cms version 2019.
To fix the CVE-2020-19957 vulnerability, it is recommended to update to a patched version of zz cms or apply the appropriate security patches provided by the vendor.