CVE-2022-4961
MEDIUMWeitong Mall 1.0.0 - SQL Injection via OrderDao.xml sidx/order Parameter
Title source: llmDescription
A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file platform-shop\src\main\resources\com\platform\dao\OrderDao.xml. The manipulation of the argument sidx/order leads to sql injection. The associated identifier of this vulnerability is VDB-250243.
References (3)
Core 3
Core References
Third Party Advisory vdb-entry
technical-description
https://vuldb.com/?id.250243
Permissions Required, Third Party Advisory signature
permissions-required
https://vuldb.com/?ctiid.250243
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://gitee.com/fuyang_lipengjun/platform/issues/I5XC79
Scores
CVSS v3
5.5
EPSS
0.0007
EPSS Percentile
22.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
fuyanglipengjun/wetong_mall
1.0.0
Published
Jan 12, 2024
Tracked Since
Feb 18, 2026