A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.
Conclusion & alert: CVE-2018-17852 is rated High Exploit Risk (80.5/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.54%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.27% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2018-17852
Exploit prediction scoring system (EPSS) score for CVE-2018-17852
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).