Vulnerability Description
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vtimecn | 188Jianzhan | 2.10 |
Related Weaknesses (CWE)
References
- https://github.com/vtime-tech/188Jianzhan/issues/2ExploitIssue TrackingThird Party Advisory
- https://github.com/vtime-tech/188Jianzhan/issues/2ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-23685?
CVE-2020-23685 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
How severe is CVE-2020-23685?
CVE-2020-23685 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-23685?
Check the references section above for vendor advisories and patch information. Affected products include: Vtimecn 188Jianzhan.