CVE-2020-19888

MEDIUM

DBHcms 1.2.0 - Unauthenticated Unauthorized Cache Clearing via page.php

Title source: llm
STIX 2.1

Description

DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0074
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
dbhcms_project/dbhcms 1.2.0
Published Aug 24, 2020
Tracked Since Feb 18, 2026