Record summary

CVE-2021-41460 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHECShop 4.1.0 - SQL InjectionCVSS 7.5

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data manipulation, or data leakage.

Remediation

Apply the latest patch or upgrade to a newer version of ECShop to mitigate the SQL Injection vulnerability (CVE-2021-41460).

WeaknessesCWE-89
AuthorsSleepingBag945
Template tagscve2021cvecnvdcnvd2020ecshopsqlishopexvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:shopex:ecshop:4.1.0:*:*:*:*:*:*:*
FOFA: product="ECShop"
FOFA: product="ecshop"

Source: ProjectDiscovery

References

2