Security Advisory

CVE-2020-19959

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-10-14 14:17:33
Last updated 2024-08-04 14:15:28
Assigner mitre
State PUBLISHED

Description

A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.