Review reviewHigh
CVE-2020-23630
zzcms
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
- CVSS
- 8.8
- EPSS
- 1.20% 65.1% percentile
- CISA KEV
- Not listed
- Published
- 2021.01.12
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
The CVSS severity warrants an early asset and exposure review.
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
Confirm exposure before applying a vendor-supported change.
Confirm that zzcms and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.