CRITICAL

CVE-2019-13086

CVSS v3

9.8

CRITICAL

EPSS Score

50.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.

Technical details

Published
6/30/2019

Frequently asked questions

What is CVE-2019-13086?

core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.

Is CVE-2019-13086 actively exploited?

Active exploitation of CVE-2019-13086 has not been confirmed. The EPSS score is 50.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-13086?

CVE-2019-13086 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-13086 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.