CVE-2020-22198: SQL Injection
Published Jun 16, 2021
·Updated
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajaxmembergroup.php.
Affected Software
1 affected component
DedeCMS Dedecms=5.7
Event History
Jun 16, 2021
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22198?
The severity of CVE-2020-22198 is critical.
2
How does the SQL Injection vulnerability in DedeCMS 5.7 occur?
The SQL Injection vulnerability in DedeCMS 5.7 occurs through the use of the mdescription parameter in the member/ajax_membergroup.php file.
3
Which version of DedeCMS is affected by CVE-2020-22198?
Version 5.7 of DedeCMS is affected by CVE-2020-22198.
4
Are there any public references for CVE-2020-22198?
Yes, there are public references available for CVE-2020-22198. You can find them at the following links: [http://www.hackdig.com/?02/hack-8391.htm](http://www.hackdig.com/?02/hack-8391.htm) and [https://github.com/blindkey/DedeCMSv5/issues/1](https://github.com/blindkey/DedeCMSv5/issues/1).
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-22198?
The Common Weakness Enumeration (CWE) ID for CVE-2020-22198 is 89.