Record summary

CVE-2020-22211 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICAL74cms - ajax_street.php 'key' SQL InjectionCVSS 9.8

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the 'key' parameter of ajax_street.php in 74cms.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve202074cmssqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:74cms:74cms:3.2.0:*:*:*:*:*:*:*
Shodan: http.html:"74cms"
FOFA: app="74cms"
FOFA: body="74cms"

Source: ProjectDiscovery

References

2