S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-22210 Scanner

CVE-2020-22210 scanner - SQL Injection vulnerability in 74 CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-22210
9.8
CVSS

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

74 CMS is a content management system that is extensively used by various websites to manage their digital assets, including text, video, audio, and images. It is an open-source platform that allows website administrators to edit, update, and publish content easily. With 74 CMS, webmasters can create and manage multiple users, who can also access the system and publish content. The platform is robust, user-friendly, and flexible, making it a popular choice for website administrators.

Recently, a vulnerability was detected in 74cms 3.2.0 that can allow hackers to inject SQL queries into the system via the x parameter to ajax_officebuilding.php. This vulnerability is known as CVE-2020-22210 and has been categorized as a high-risk vulnerability. Hackers can exploit this vulnerability to gain unauthorized access to the system, extract sensitive information, modify, or delete existing data. All affected websites that use 74cms 3.2.0 are at risk of falling prey to this attack.

The CVE-2020-22210 vulnerability can lead to severe consequences when exploited. Hackers can steal sensitive user data, including personally identifiable information (PII), financial information, login credentials, and other sensitive information. The attackers can use this information to launch targeted phishing attacks, blackmailing, or sell the information on the dark web. Additionally, this vulnerability can allow hackers to modify or delete critical system files, leading to crashes and denial-of-service attacks, disrupting the website's operations.

In conclusion, website administrators must take proactive measures to protect their digital assets from vulnerabilities such as CVE-2020-22210 in 74cms 3.2.0. The s4e.io platform provides cutting-edge security features that can help you detect and eliminate such vulnerabilities quickly and efficiently. By leveraging the pro features of the s4e.io platform, users can enjoy enhanced security and improved threat detection. Protect your digital assets by staying up-to-date on the latest security vulnerabilities and ensuring you implement the appropriate security measures.

 

REFERENCES

Solution Advice

Website administrators can take several precautions to protect against this vulnerability. These include;

  • Update the affected software to the latest version.
  • Disable or block access to the vulnerable ajax_officebuilding.php file.
  • Implement web application firewalls to block malicious SQL queries.
  • Regularly scan your website for vulnerabilities and detect any potential threats.
  • Back up your website frequently to avoid losing critical data.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-22210 scanner - SQL Injection vulnerability in 74 CMS | S4E