Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-95249
HistoryDec 04, 2021 - 12:00 a.m.

ecshop SQL Injection Vulnerability (CNVD-2021-95249)

2021-12-0400:00:00
China National Vulnerability Database
www.cnvd.org.cn
6

0.002 Low

EPSS

Percentile

54.6%

ECShop is an open source mall system from Business School. Support PC H5 APP small program mall, source code free download experience, suitable for enterprise development build mall. ecshop in v2.7.3 version there is a SQL injection vulnerability, the vulnerability stems from ecshop database based applications lack of validation of external input SQL statements. An attacker could use this vulnerability to execute illegal SQL commands.

CPENameOperatorVersion
shopex ecshop veq2.7.3

0.002 Low

EPSS

Percentile

54.6%

Related for CNVD-2021-95249