CVE-2018-7579

Publication date

2018-03-01 18:00:00

Family

mitre

State

PUBLISHED

Description

applicationadmincontrollerupdate_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.