ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-18877”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-18877
Published
2021-08-20
CVSS:
7.5
ShadowTrackr CVSS:
4.6
Summary:
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.