SQL Injection Vulnerability in zzcms 2019 by cby234
CVE-2019-12352

8.8HIGH

Key Information:

Vendor

Zzcms

Status
Vendor
CVE Published:
17 June 2022

What is CVE-2019-12352?

A vulnerability has been discovered in zzcms 2019 that allows for SQL injection through the /dl/dl_sendmail.php endpoint. This issue arises when an attacker with dls_print authority can manipulate the dlid cookie to execute unauthorized SQL commands, potentially compromising the database. It is crucial for users and administrators of zzcms 2019 to implement safeguards against this type of attack.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.