CVE-2020-37108

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
03/02/2026
Last modified:
03/02/2026

Description

PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the 'id' parameter to potentially extract or modify database information.