CVE-2018-12912: Hongcms Project Hongcms

High severity, CVSS 7.2. EPSS: 2.6% chance of exploitation in the next 30 days.

An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.

Affected products

Published 2018-06-27. Last modified 2026-06-17.