SQL Injection Vulnerability in WUZHI CMS 4.1.0 by WUZHI
CVE-2018-14515
9.8CRITICAL
Summary
A vulnerability in WUZHI CMS version 4.1.0 allows attackers to execute unauthorized SQL commands through the 'keywords' parameter in the index.php file. This flaw could lead to unauthorized access and manipulation of the database, putting sensitive information at risk. It is crucial to apply mitigations and stay updated to prevent exploitation of this weakness.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved