An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
References
Link Resource
https://github.com/wuzhicms/wuzhicms/issues/144 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:22:28

Updated: 2022-10-03T16:22:28

Reserved: 2022-10-03T00:00:00


Link: CVE-2018-14472

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-07-20T16:29:00.510

Modified: 2018-09-14T14:03:47.557


Link: CVE-2018-14472

JSON object: View

cve-icon Redhat Information

No data.

CWE