An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.
- https://github.com/cby234/zzcms/issues/5
- https://github.com/ARPSyndicate/cvemon
- https://github.com/brejoc/bscdiff