First published: Thu Dec 09 2021(Updated: )
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =8.2 | |
Zzcms Zzcms | =8.3 | |
Zzcms Zzcms | =2020 | |
Zzcms Zzcms | =2021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40282 is an SQL Injection vulnerability in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_download.php when registering ordinary users.
The severity of CVE-2021-40282 is high with a CVSS score of 8.8.
The SQL Injection vulnerability in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_download.php occurs when registering ordinary users.
Versions 8.2, 8.3, 2020, and 2021 of zzcms are affected by CVE-2021-40282.
To fix the SQL Injection vulnerability, update zzcms to a patched version provided by the vendor.