Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56495
HistoryJun 17, 2022 - 12:00 a.m.

kkcms SQL Injection Vulnerability

2022-06-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
kkcms
sql injection
v1.3.7
vulnerability
database data
video capture

EPSS

0.002

Percentile

54.5%

kkcms is an open source video capture and playback system. The system is mainly used to automatically capture video resources and provide online playback. kkcms v1.3.7 version has a SQL injection vulnerability, the vulnerability originates from /template/wapian/vlist.php does not filter the incoming cid parameter. An attacker can use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-56495