CVE-2018-16278

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
31/08/2018
Last modified:
23/10/2018

Description

phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpkaiyuancms:phpopensourcecms:3.2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools