CVE-2021-22847

Publication date

2021-01-22 08:30:20

Family

twcert

State

PUBLISHED

Description

Hyweb HyCMS-J1s API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands without privilege.