CVE-2021-41649
online-shopping-system-advanced_project online-shopping-system-advanced Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2021-41649 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
online-shopping-system-advancedBrowse online-shopping-system-advanced_project / online-shopping-system-advanced | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPuneethReddyHC Online Shopping System homeaction.php SQL InjectionCVSS 9.8
An unauthenticated SQL injection vulnerability exists in PuneethReddyHC Online Shopping System through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery