An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.
- https://github.com/Neeke/HongCMS/issues/4
- https://www.exploit-db.com/exploits/44953/
No PoCs found on GitHub currently.