ZeroHour

CVE-2018-7474

PoC ×2
CVSS 3.0
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.

Vendors
textpattern
Products
textpattern
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.