SQL Injection Vulnerability in Gxlcms v2.0 via ids[] Parameter

SQL Injection Vulnerability in Gxlcms v2.0 via ids[] Parameter

CVE-2018-18488 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.