Vulnerability Description
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yccms | Yccms | 3.3 |
Related Weaknesses (CWE)
References
- http://www.yccms.net/ProductVendor AdvisoryURL Repurposed
- https://blog.jiguang.xyz/posts/yccms-sql-injection/ExploitThird Party Advisory
- http://www.yccms.net/ProductVendor AdvisoryURL Repurposed
- https://blog.jiguang.xyz/posts/yccms-sql-injection/ExploitThird Party Advisory
FAQ
What is CVE-2020-20289?
CVE-2020-20289 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
How severe is CVE-2020-20289?
CVE-2020-20289 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-20289?
Check the references section above for vendor advisories and patch information. Affected products include: Yccms Yccms.