CVE-2021-37593
CRITICALPeel Shopping - SQL Injection
Title source: ruleDescription
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.
Exploits (1)
References (3)
Scores
CVSS v3
9.1
EPSS
0.0070
EPSS Percentile
72.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-89
Status
published
Products (1)
peel/peel_shopping
9.4.0
Published
Jul 30, 2021
Tracked Since
Feb 18, 2026