Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99763
HistoryDec 12, 2021 - 12:00 a.m.

zzcms SQL Injection Vulnerability (CNVD-2021-99763)

2021-12-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
4

0.001 Low

EPSS

Percentile

37.7%

ZZCMS is a content management system (CMS) from the Zzcms team in China. zzcms is vulnerable to SQL injection, which allows an attacker to use the id parameter in admin/bad.php with a lack of validation for external input SQL statements. An attacker can use the vulnerability to execute illegal SQL commands to steal sensitive database data.

CPENameOperatorVersion
zzcms zzcmseq8.3
zzcms zzcmseq8.2

0.001 Low

EPSS

Percentile

37.7%

Related for CNVD-2021-99763