SQL Injection Vulnerability in WUZHI CMS Affects Multiple Versions
CVE-2018-11528
9.8CRITICAL
What is CVE-2018-11528?
WUZHI CMS version 4.1.0 is vulnerable to SQL Injection through the endpoint api/sms_check.php?param=. Attackers can exploit this vulnerability to execute arbitrary SQL commands, potentially compromising the integrity of the database and exposing sensitive information.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
