Record summary

CVE-2020-22210 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICAL74cms - ajax_officebuilding.php SQL InjectionCVSS 9.8

A SQL injection vulnerability exists in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 74cms - ajax_officebuilding.php file.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve202074cmssqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:74cms:74cms:3.2.0:*:*:*:*:*:*:*
Shodan: http.html:"74cms"
FOFA: app="74cms"
FOFA: body="74cms"

Source: ProjectDiscovery

References

2