vendor:
cxuucms
by:
icekam
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: cxuucms
Affected Version From: cxuucms - v3
Affected Version To: cxuucms - v3
Patch Exists: YES
Related CWE: CVE-2020-28091
CPE: a:cxuu:cxuucms:3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
xuucms 3 – ‘keywords’ SQL Injection
SQL injection exists in search.php. An attacker can use SQLMAP authentication to exploit the vulnerability. For details, please refer to: https://github.com/cbkhwx/cxuucmsv3/issues/1
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.