Record summary

CVE-2020-22208 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICAL74cms - ajax_street.php 'x' SQL InjectionCVSS 9.8

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the underlying database.

Remediation

Apply the vendor-provided patch or update to the latest version of 74cms to mitigate the SQL Injection vulnerability.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscve2020cve74cmssqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:74cms:74cms:3.2.0:*:*:*:*:*:*:*
Shodan: http.html:"74cms"
FOFA: app="74cms"
FOFA: body="74cms"

Source: ProjectDiscovery

References

2