Phpcms · Phpcms · CVE-2020-18263
Name of the Vulnerable Software and Affected Versions:
PHP-CMS version 1.0
Description:
The issue allows attackers to access sensitive database information through a SQL injection vulnerability in the search.php component via the `search` parameter.
Recommendations:
For PHP-CMS version 1.0, as a temporary workaround, consider restricting access to the search.php component until a patch is available. Avoid using the `search` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.