An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.
References
Link Resource
https://github.com/wuzhicms/wuzhicms/issues/198 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-20T14:32:47

Updated: 2021-09-20T14:32:46

Reserved: 2021-09-07T00:00:00


Link: CVE-2021-40674

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-20T15:15:08.990

Modified: 2021-09-28T17:57:03.710


Link: CVE-2021-40674

JSON object: View

cve-icon Redhat Information

No data.

CWE