Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pandora1M2

#29262of 53,635
8.8Total CVSS
Vulnerabilities · 1
PT-2021-10918
8.8
2021-01-11
Zzcms · Zzcms · CVE-2020-23630
**Name of the Vulnerable Software and Affected Versions** zzcms version ver201910 **Description** A blind SQL injection issue exists, based on time, and is related to cookie injection. **Recommendations** For zzcms version ver201910, consider restricting access to sensitive areas of the application to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using potentially vulnerable cookie parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.