nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-41460 CVE-2021-41460
HIGHNuclei
ECShop 4.1.0 - SQL Injection
Record summary
CVE-2021-41460 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHECShop 4.1.0 - SQL InjectionCVSS 7.5
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.
Remediation
Apply the latest patch or upgrade to a newer version of ECShop to mitigate the SQL Injection vulnerability (CVE-2021-41460).
WeaknessesCWE-89
AuthorsSleepingBag945
Template tagscve2021cvecnvdcnvd2020ecshopsqlishopexvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:shopex:ecshop:4.1.0:*:*:*:*:*:*:*
FOFA: product="ECShop"
FOFA: product="ecshop"
Source: ProjectDiscovery
References
2cnvd.org.cn
https://www.cnvd.org.cn/flaw/show/CNVD-2020-58823