Lucene search

K
osvGoogleOSV:CVE-2018-19897
HistoryDec 06, 2018 - 4:29 a.m.

CVE-2018-19897

2018-12-0604:29:00
Google
osv.dev
3

8.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.7%

ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action.

8.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.7%

Related for OSV:CVE-2018-19897