foreversong.cn
http://foreversong.cn/archives/1183 CVE-2018-11231
HIGHNuclei
Opencart Divido - Sql Injection
Record summary
CVE-2018-11231 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.
Description
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHOpencart Divido - Sql InjectionCVSS 8.1
OpenCart Divido plugin is susceptible to SQL injection
Impact
This vulnerability can lead to data theft, unauthorized access, and potential compromise of the entire Opencart Divido system.
Remediation
Apply the official patch or upgrade to a version that includes the fix.
WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2018opencartsqliintrusivedividovuln
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:divido:divido:-:*:*:*:*:opencart:*:*
https://web.archive.org/web/20220331072310/http://foreversong.cn/archives/1183 https://nvd.nist.gov/vuln/detail/CVE-2018-11231 http://foreversong.cn/archives/1183 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-11231