SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.
References
Link Resource
https://github.com/wuzhicms/wuzhicms/issues/197 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-16T18:45:25

Updated: 2021-09-16T18:45:25

Reserved: 2021-09-07T00:00:00


Link: CVE-2021-40670

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-16T19:15:07.977

Modified: 2021-09-27T20:47:20.703


Link: CVE-2021-40670

JSON object: View

cve-icon Redhat Information

No data.

CWE