{"api_version":"1","generated_at":"2026-07-23T12:46:19+00:00","cve":"CVE-2020-7356","urls":{"html":"https://cve.report/CVE-2020-7356","api":"https://cve.report/api/cve/CVE-2020-7356.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-7356","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-7356"},"summary":{"title":"CVE-2020-7356","description":"CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.","state":"PUBLIC","assigner":"cve@rapid7.com","published_at":"2020-08-06 16:15:00","updated_at":"2020-08-12 13:39:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://github.com/rapid7/metasploit-framework/pull/13607","name":"https://github.com/rapid7/metasploit-framework/pull/13607","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Cayin xPost and CMS exploits by h00die · Pull Request #13607 · rapid7/metasploit-framework · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5571.php","name":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5571.php","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Zero Science Lab » Cayin Digital Signage System xPost 2.5 Pre-Auth SQLi Remote Code Execution","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-7356","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7356","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"This issue was discovered by Gjoko Krstic of Zero Science Lab.","lang":""}],"nvd_cpes":[{"cve_year":"2020","cve_id":"7356","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cayintech","cpe5":"xpost","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7356","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cayintech","cpe5":"xpost","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7356","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cayintech","cpe5":"xpost","cpe6":"2.5.18103","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7356","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cayintech","cpe5":"xpost","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7356","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cayintech","cpe5":"xpost","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7356","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cayintech","cpe5":"xpost","cpe6":"2.5.18103","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@rapid7.com","DATE_PUBLIC":"2020-04-06T10:00:00.000Z","ID":"CVE-2020-7356","STATE":"PUBLIC","TITLE":"Cayin xPost SQL Injection"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Cayin xPost","version":{"version_data":[{"version_affected":"=","version_name":"2.5.18103","version_value":"2.5.18103"},{"version_affected":"=","version_name":"2.0","version_value":"2.0"},{"version_affected":"=","version_name":"1.0","version_value":"1.0"}]}}]},"vendor_name":"Cayin Technology"}]}},"credit":[{"lang":"eng","value":"This issue was discovered by Gjoko Krstic of Zero Science Lab."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-89 SQL Injection"}]}]},"references":{"reference_data":[{"name":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5571.php","refsource":"MISC","url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5571.php"},{"name":"https://github.com/rapid7/metasploit-framework/pull/13607","refsource":"MISC","url":"https://github.com/rapid7/metasploit-framework/pull/13607"}]},"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2020-08-06 16:15:00","lastModifiedDate":"2020-08-12 13:39:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cayintech:xpost:2.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cayintech:xpost:1.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cayintech:xpost:2.5.18103:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"7356","Ordinal":"167635","Title":"CVE-2020-7356","CVE":"CVE-2020-7356","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"7356","Ordinal":"1","NoteData":"CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"7356","Ordinal":"2","NoteData":"2020-08-06","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"7356","Ordinal":"3","NoteData":"2020-08-06","Type":"Other","Title":"Modified"}]}}}