First published: Mon May 08 2023(Updated: )
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Victor Cms Project Victor Cms | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23966 is a SQL Injection vulnerability in Victor CMS 1.0 that allows attackers to execute arbitrary commands via a crafted GET request.
CVE-2020-23966 has a severity rating of 9.8 (Critical).
CVE-2020-23966 affects Victor CMS 1.0 by allowing attackers to execute arbitrary commands via the post parameter in a crafted GET request.
To fix CVE-2020-23966, it is recommended to update to the latest version of Victor CMS with the security patch.
Yes, you can find references for CVE-2020-23966 at the following links: [Github Issue](https://github.com/VictorAlagwu/CMSsite/issues/15) and [Github Repository](https://github.com/VictorAlagwu/CMSsite/).