CVE-2023-46482

SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wuzhicms:wuzhicms:4.1.0:*:*:*:*:*:*:*

History

09 Nov 2023, 00:56

Type Values Removed Values Added
First Time Wuzhicms
Wuzhicms wuzhicms
CWE CWE-89
CPE cpe:2.3:a:wuzhicms:wuzhicms:4.1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://github.com/XTo-o1/PHP/blob/main/wuzhicms/WUZHI%20CMS%20v4.1.0%20SQL%20Injection%20Vulnerability%20in%20Database%20Backup%20Functionality.md - (MISC) https://github.com/XTo-o1/PHP/blob/main/wuzhicms/WUZHI%20CMS%20v4.1.0%20SQL%20Injection%20Vulnerability%20in%20Database%20Backup%20Functionality.md - Exploit

01 Nov 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-01 19:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-46482

Mitre link : CVE-2023-46482

CVE.ORG link : CVE-2023-46482


JSON object : View

Products Affected

wuzhicms

  • wuzhicms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')