CVE-2020-21378: SQL Injection
Published Dec 21, 2020
·Updated
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to adminmembersgroup.php.
Affected Software
1 affected component
SEACMS SEACMS=10.1
Event History
Dec 21, 2020
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
Description
Frequently Asked Questions
1
What is CVE-2020-21378?
CVE-2020-21378 is a SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) through the id parameter in an edit action to admin_members_group.php.
2
How severe is CVE-2020-21378?
CVE-2020-21378 has a severity rating of 9.8 (Critical).
3
How does CVE-2020-21378 affect SeaCMS?
CVE-2020-21378 affects SeaCMS version 10.1.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-21378?
The CWE ID for CVE-2020-21378 is CWE-89 (SQL Injection).
5
How can I fix the SQL injection vulnerability in SeaCMS 10.1?
To fix the SQL injection vulnerability in SeaCMS 10.1, it is recommended to update to a patched version provided by the vendor.