CVE-2020-20392: Txjia Imcat

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.

Affected products

  • Txjia Imcat: version 5.2 only

Published 2021-06-23. Last modified 2026-06-17.