High severity8.2NVD Advisory· Published May 16, 2026· Updated May 18, 2026
CVE-2020-37242
CVE-2020-37242
Description
Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based blind or time-based blind SQL injection payloads to extract sensitive database information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: =1.1.12
- Range: =1.1.12
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.