vendor:
202CMS
by:
Mehmet EMIROGLU
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: 202CMS
Affected Version From: v10 beta
Affected Version To: v10 beta
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Wamp64, Windows
2019
202CMS – ‘log_user’ SQL Inj.
The 202CMS version v10 beta is vulnerable to SQL Injection via the 'log_user' parameter. An attacker can exploit this vulnerability to execute arbitrary SQL commands on the underlying database.
Mitigation:
Apply the latest patch or upgrade to a version that is not vulnerable.