CVE-2020-21394: SQL Injection
Published Jun 29, 2021
·Updated
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
Affected Software
2 affected components
crmeb crmeb=2.60
crmeb crmeb=3.1
Event History
Jun 29, 2021
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-21394?
CVE-2020-21394 is classified as a critical severity vulnerability due to its potential for SQL Injection.
2
How do I fix CVE-2020-21394?
To fix CVE-2020-21394, update your CRMEB mall system to version 3.1 or apply available patches that address the SQL Injection issue.
3
Which versions of CRMEB are affected by CVE-2020-21394?
CVE-2020-21394 affects CRMEB versions 2.60 and 3.1.
4
What type of vulnerability is CVE-2020-21394?
CVE-2020-21394 is an SQL Injection vulnerability, allowing attackers to manipulate database queries.
5
Where can I find more information about CVE-2020-21394?
You can find more information about CVE-2020-21394 in documentation pertaining to SQL Injection vulnerabilities in CRMEB.