Vulnerability Description
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zzcms | Zzcms | 2018 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/96.htmlThird Party Advisory
- https://github.com/seabird1992/TEST123/blob/master/071711233468_0zzcms.pdfExploitThird Party Advisory
- https://cwe.mitre.org/data/definitions/96.htmlThird Party Advisory
- https://github.com/seabird1992/TEST123/blob/master/071711233468_0zzcms.pdfExploitThird Party Advisory
FAQ
What is CVE-2020-19822?
CVE-2020-19822 is a vulnerability with a CVSS score of 7.2 (HIGH). A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
How severe is CVE-2020-19822?
CVE-2020-19822 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-19822?
Check the references section above for vendor advisories and patch information. Affected products include: Zzcms Zzcms.