CVE-2021-43701
29.03.2022, 16:15
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.
Vendor | Product | Version |
---|---|---|
cszcms | csz_cms | 1.2.9 |
𝑥
= Vulnerable software versions
References