Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-103373
HistoryOct 31, 2021 - 12:00 a.m.

Online Shopping Portal SQL Injection Vulnerability (CNVD-2021-103373)

2021-10-3100:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
online shopping
sql injection
vulnerability
version 3.1
external input
database theft

EPSS

0.002

Percentile

58.5%

Online Shopping Portal is an open source online shopping portal. Online Shopping Portal is vulnerable to SQL injection in version 3.1, where an attacker can use the email parameter on the /check_availability.php endpoint to lack validation of external input SQL statements. An attacker can use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

58.5%

Related for CNVD-2021-103373