SQL Injection Vulnerability in Wuzhicms by Wuzhicms Team
CVE-2023-46482

9.8CRITICAL

Key Information:

Vendor

Wuzhicms

Status
Vendor
CVE Published:
1 November 2023

What is CVE-2023-46482?

A SQL injection vulnerability exists in Wuzhicms v4.1.0, specifically within the coreframe/app/database/admin/index.php component. This flaw enables a remote attacker to exploit the Database Backup functionality, potentially allowing for the execution of arbitrary code. Proper input validation and sanitization are crucial to mitigate this risk and protect against unauthorized access and data manipulation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.