SQL Injection Vulnerability in zzcms Product by cby234
CVE-2019-12350
9.8CRITICAL
What is CVE-2019-12350?
An SQL Injection vulnerability has been identified in the zzcms product, specifically in the file dl/dl_download.php. This vulnerability can be triggered through the 'id' parameter when it contains a trailing comma, potentially allowing attackers to execute unauthorized SQL commands. This issue exposes the underlying database to manipulation and can lead to unauthorized data access or even data loss.