CVE-2018-16436 Information
Feb 14, 2021
cve
Description
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
http://bbs.gxlcms.com/forum.php?mod=viewthread&tid=787&extra=page3D1 http://www.ttk7.cn/post-77.html https://exchange.xforce.ibmcloud.com/vulnerabilities/149624
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: