CVE-2015-7791

MEDIUM

Collne Welcart <1.5.3 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) search[column] or (2) switch parameter.

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN43344629/index.html
Vendor Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000200
Vendor Advisory x_refsource_confirm
http://www.welcart.com/community/archives/76035
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/8356
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/79647

Scores

CVSS v3 6.3
EPSS 0.0158
EPSS Percentile 72.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-89
Status published
Products (1)
welcart/welcart_e-commerce < 1.5.2
Published Dec 29, 2015
Tracked Since Feb 18, 2026