SQL Injection Vulnerability in Wuzhicms by Wuzhicms Team
CVE-2023-46482
9.8CRITICAL
What is CVE-2023-46482?
A SQL injection vulnerability exists in Wuzhicms v4.1.0, specifically within the coreframe/app/database/admin/index.php component. This flaw enables a remote attacker to exploit the Database Backup functionality, potentially allowing for the execution of arbitrary code. Proper input validation and sanitization are crucial to mitigate this risk and protect against unauthorized access and data manipulation.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
