CVE-2020-37110 | Davidvg 60CycleCMS 2.5.2 Query Parameter news.php sql injection (Exploit 48177 / EUVD-2020-30985)
A vulnerability classified as critical has been found in Davidvg 60CycleCMS 2.5.2. Affected is an unknown function in the library common/lib.php of the file news.php of the component Query Parameter Handler. This manipulation causes sql injection.
This vulnerability is registered as CVE-2020-37110. Remote exploitation of the attack is possible. Furthermore, an exploit is available.