Record summary

CVE-2018-11231 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.

Description

In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHOpencart Divido - Sql InjectionCVSS 8.1

OpenCart Divido plugin is susceptible to SQL injection

Impact

This vulnerability can lead to data theft, unauthorized access, and potential compromise of the entire Opencart Divido system.

Remediation

Apply the official patch or upgrade to a version that includes the fix.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2018opencartsqliintrusivedividovuln
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:divido:divido:-:*:*:*:*:opencart:*:*

Source: ProjectDiscovery

References

2