Vulnerability Description
controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and the parameter 'module' with a SQL statement, lacks effective filtering.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Finecms | Finecms | 5.2.0 |
Related Weaknesses (CWE)
References
- https://xianzhi.aliyun.com/forum/topic/2050Broken Link
- https://xianzhi.aliyun.com/forum/topic/2050Broken Link
FAQ
What is CVE-2018-6893?
CVE-2018-6893 is a vulnerability with a CVSS score of 9.8 (CRITICAL). controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and the parameter 'module' with a SQL statement, lacks effective filtering.
How severe is CVE-2018-6893?
CVE-2018-6893 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-6893?
Check the references section above for vendor advisories and patch information. Affected products include: Finecms Finecms.