github.com
https://github.com/blindkey/cve_like/issues/11 CVE-2020-22210
CRITICALNuclei
74cms - ajax_officebuilding.php SQL Injection
Record summary
CVE-2020-22210 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICAL74cms - ajax_officebuilding.php SQL InjectionCVSS 9.8
A SQL injection vulnerability exists in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 74cms - ajax_officebuilding.php file.
WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve202074cmssqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:74cms:74cms:3.2.0:*:*:*:*:*:*:*
Shodan: http.html:"74cms"
FOFA: app="74cms"
FOFA: body="74cms"
https://github.com/blindkey/cve_like/issues/11 https://nvd.nist.gov/vuln/detail/CVE-2020-22210 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-22210