Summary: In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.Published: Thursday, October 18, 2018 - 17:29cvss: