SQL Injection Vulnerability in DuomiCMS 3.0 by Duomi
CVE-2018-18084
9.8CRITICAL
What is CVE-2018-18084?
A SQL injection vulnerability exists in DuomiCMS 3.0 within the ajax.php file, specifically via the uid parameter. This flaw could allow an attacker to manipulate SQL queries, potentially leading to unauthorized access or exposure of sensitive data. Proper input validation and sanitization measures are recommended to mitigate this security risk.
