SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Feb 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Niushop
Niushop b2b2c Multi-business |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:niushop:b2b2c_multi-business:5.0:*:*:*:*:*:*:* | |
Vendors & Products |
Niushop
Niushop b2b2c Multi-business |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-02-26T00:00:00
Updated: 2024-08-26T18:51:42.417Z
Reserved: 2024-02-07T00:00:00
Link: CVE-2024-25248

Updated: 2024-08-01T23:44:08.343Z

Status : Analyzed
Published: 2024-02-26T22:15:07.003
Modified: 2025-02-14T16:22:09.803
Link: CVE-2024-25248

No data.