CVE-2018-7579

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
01/03/2018
Last modified:
22/03/2018

Description

\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yzmcms:yzmcms:3.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools