PT-2020-15604 · Victor · Victor Cms

Ztxyzwd

·

Published

2020-10-27

·

Updated

2020-10-27

·

CVE-2020-23945

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Victor CMS version V1.0
Description A SQL injection issue exists in the cat id parameter of the category.php file, allowing potential access to database information through tools like sqlmap.
Recommendations For Victor CMS version V1.0, consider restricting access to the category.php file or the cat id parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23945

Affected Products

Victor Cms