CVE-2019-13086
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
- Affected products
- Csz Cms
- Cszcms Csz Cms
- ≤ 1.2.2
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 32.0% (98th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2019-06-30
CVE-2019-13086 at NVD
1 known exploit for CVE-2019-13086
Proof-of-concept code and exploit modules indexed by Sploitus