CVE-2020-19888

MEDIUM

Dbhcms - Authentication Bypass

Title source: rule
STIX 2.1

Description

DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0021
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
dbhcms_project/dbhcms 1.2.0
Published Aug 24, 2020
Tracked Since Feb 18, 2026