Vulnerability Description
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecisp | Espcms-P8 | - |
Related Weaknesses (CWE)
References
- http://tusk1.cn/2019/03/21/ESPCMS-P8%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E4%BExploitThird Party Advisory
- http://tusk1.cn/2019/03/21/ESPCMS-P8%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E4%BExploitThird Party Advisory
FAQ
What is CVE-2020-18913?
CVE-2020-18913 is a vulnerability with a CVSS score of 7.5 (HIGH). EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive ...
How severe is CVE-2020-18913?
CVE-2020-18913 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-18913?
Check the references section above for vendor advisories and patch information. Affected products include: Ecisp Espcms-P8.