SQL Injection Vulnerability in zzcms by cby234
CVE-2019-12355

8.8HIGH

Key Information:

Vendor

Zzcms

Status
Vendor
CVE Published:
17 June 2022

What is CVE-2019-12355?

In zzcms 2019, a SQL injection vulnerability exists in the /user/dls_print.php script which can be exploited by an attacker with dls_print authority by manipulating the id parameter. This flaw can allow unauthorized access to sensitive data, potentially leading to further exploitation of the system and compromise of user information.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.