Baijiacms · Baijiacms · CVE-2019-7568
**Name of the Vulnerable Software and Affected Versions**
baijiacms version V4
**Description**
The issue allows for time-based blind SQL injection, enabling data retrieval via the `cate` parameter in an "index.php?act=index" request.
**Recommendations**
For baijiacms version V4, consider restricting access to the "index.php?act=index" endpoint to minimize the risk of exploitation. Avoid using the `cate` parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.