Zzcms · Zzcms · CVE-2020-23630
**Name of the Vulnerable Software and Affected Versions**
zzcms version ver201910
**Description**
A blind SQL injection issue exists, based on time, and is related to cookie injection.
**Recommendations**
For zzcms version ver201910, consider restricting access to sensitive areas of the application to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using potentially vulnerable cookie parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.