SQL Injection Vulnerability in zzcms 2019 by cby234
CVE-2019-12352
8.8HIGH
What is CVE-2019-12352?
A vulnerability has been discovered in zzcms 2019 that allows for SQL injection through the /dl/dl_sendmail.php endpoint. This issue arises when an attacker with dls_print authority can manipulate the dlid cookie to execute unauthorized SQL commands, potentially compromising the database. It is crucial for users and administrators of zzcms 2019 to implement safeguards against this type of attack.