Cscms · Cscms · CVE-2020-28102
**Name of the Vulnerable Software and Affected Versions**
cscms version 4.1
**Description**
The issue allows for SQL injection via the `js del` function. This enables potential attackers to inject malicious SQL code, which could lead to unauthorized access or manipulation of database content.
**Recommendations**
For cscms version 4.1, consider disabling the `js del` function as a temporary workaround until a patch is available. Restrict access to sensitive database operations to minimize the risk of exploitation.