Vulnerability Details CVE-2020-21649
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.6%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 5.5
Products affected by CVE-2020-21649
-
cpe:2.3:a:myucms_project:myucms:2.2