CVE-2021-41460

HIGH NUCLEI

Shopex Ecshop - SQL Injection

Title source: rule

Description

ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

Nuclei Templates (1)

ECShop 4.1.0 - SQL Injection
HIGHVERIFIEDby SleepingBag945
FOFA: product="ECShop" || product="ecshop"

Scores

CVSS v3 7.5
EPSS 0.4471
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
shopex/ecshop 4.1.0
Published Jun 28, 2022
Tracked Since Feb 18, 2026