ZeroHour

CVE-2020-18019

PoC
CVSS 3.1
7.5 high
EPSS
2%p73
Published
()
Modified
Description

SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.

Vendors
xinfu
Products
oa system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.