PT-2024-22463 · Unknown · Niushop B2B2C

·

CVE-2024-28560

·

Published

2024-03-22

·

Updated

2024-08-23

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Niushop B2B2C versions 5.3.3 and earlier
Description The issue allows an attacker to escalate privileges via the deleteArea() function of the Address.php component or the setPrice() function of the Goodsbatchset.php component. This is a SQL injection vulnerability.
Recommendations For versions 5.3.3 and earlier, as a temporary workaround, consider disabling the deleteArea() function and the setPrice() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28560

Affected Products

Niushop B2B2C