WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin...
Critical severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Dec 28, 2018
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Feb 2, 2023
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.
References