CVE-2020-20122: SQL Injection
Published Sep 28, 2021
·Updated
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Sep 28, 2021
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-20122.
2
What is the severity of CVE-2020-20122?
The severity of CVE-2020-20122 is critical with a CVSS score of 9.8.
3
What is the affected software of CVE-2020-20122?
The affected software of CVE-2020-20122 is Wuzhi CMS v4.1.
4
What is the CWE classification of CVE-2020-20122?
The CWE classification of CVE-2020-20122 is CWE-89.
5
How can I fix the SQL injection vulnerability in Wuzhi CMS v4.1?
To fix the SQL injection vulnerability in Wuzhi CMS v4.1, you should apply the official patch or update to the latest version of the CMS.