CVE-2023-46482: SQL Injection
SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46482?
The severity of CVE-2023-46482 is critical, with a severity value of 9.8.
What is the affected software for CVE-2023-46482?
The affected software for CVE-2023-46482 is Wuzhicms version 4.1.0.
How does the SQL injection vulnerability in CVE-2023-46482 work?
The SQL injection vulnerability allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.
Is there a fix available for CVE-2023-46482?
Yes, upgrading to a newer version of Wuzhicms that has addressed the SQL injection vulnerability is recommended.
Where can I find more information about CVE-2023-46482?
You can find more information about CVE-2023-46482 at the following reference link: [Reference Link](https://github.com/XTo-o1/PHP/blob/main/wuzhicms/WUZHI%20CMS%20v4.1.0%20SQL%20Injection%20Vulnerability%20in%20Database%20Backup%20Functionality.md)