CVE-2020-20413: SQL Injection
Published Jun 20, 2023
·Updated
SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Jun 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability?
The vulnerability ID for this SQL injection vulnerability is CVE-2020-20413.
2
What is the affected software and version for this vulnerability?
The affected software and version for this vulnerability is WUZHICMS v.4.1.0.
3
What is the severity rating for this vulnerability?
The severity rating for this vulnerability is critical (9.8).
4
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by executing arbitrary code via the checktitle() function in admin/content.php.
5
Is there a fix available for this vulnerability?
Yes, it is recommended to upgrade WUZHICMS to a version that is not affected by this vulnerability.