Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-20136
HistoryMar 14, 2022 - 12:00 a.m.

Luocms SQL Injection Vulnerability (CNVD-2022-20136)

2022-03-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
luocms
sql injection
vulnerability
article management system
validation
external input
admin
sql commands
sensitive data
cnvd-2022-20136

EPSS

0.002

Percentile

54.5%

Luocms is an article management system. A SQL injection vulnerability exists in Luocms v2.0, which stems from a lack of validation of external input SQL statements in /admin/link/link_mod.php. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-20136