CVE-2020-18877: Wuzhicms
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.
Affected products
- Wuzhicms Wuzhicms: version 4.1.0 only
Published 2021-08-20. Last modified 2026-06-17.