First published: Thu Oct 14 2021(Updated: )
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19960 is a SQL injection vulnerability discovered in zz cms version 2019.
CVE-2020-19960 allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.
zz cms version 2019 is affected by CVE-2020-19960.
CVE-2020-19960 has a severity level of 7.5 (High).
To mitigate CVE-2020-19960, it is recommended to update zz cms to a patched version or apply the necessary security patches provided by the vendor.