First published: Thu Oct 14 2021(Updated: )
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability is CVE-2020-19959.
The affected software is zz cms version 2019.
Attackers can exploit this vulnerability by manipulating the dlid parameter in the /dl/dl_sendmail.php page cookie to perform SQL injection attacks and retrieve sensitive data.
The severity rating of this vulnerability is 7.5 (high).
Yes, it is recommended to update to a patched version of zz cms that addresses this SQL injection vulnerability.