CVE-2021-46204

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
19/01/2022
Last modified:
25/01/2022

Description

Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:taogogo:taocms:3.0.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools