SQL Injection Vulnerability in zz CMS 2019: Retrieval of Sensitive Data via dlid Parameter

SQL Injection Vulnerability in zz CMS 2019: Retrieval of Sensitive Data via dlid Parameter

CVE-2020-19959 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.