Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-101691
HistoryDec 19, 2021 - 12:00 a.m.

ZZCMS SQL Injection Vulnerability (CNVD-2021-101691)

2021-12-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
10

0.002 Low

EPSS

Percentile

52.2%

ZZCMS is a content management system (CMS) from the Zzcms team in China.ZZCMS is vulnerable to SQL injection in 2021, which stems from a lack of validation of external input SQL statements in the askbigclassid parameter of /admin/ask.php in the application. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

0.002 Low

EPSS

Percentile

52.2%

Related for CNVD-2021-101691