CVE-2022-4961

MEDIUM

Fuyanglipengjun Wetong Mall - SQL Injection

Title source: rule

Description

A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file platform-shop\src\main\resources\com\platform\dao\OrderDao.xml. The manipulation of the argument sidx/order leads to sql injection. The associated identifier of this vulnerability is VDB-250243.

Exploits (1)

gitee 27,648 stars
by fuyang_lipengjun · javawriteup
https://gitee.com/fuyang_lipengjun/platform/issues/I5XC79

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 22.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-89
Status published

Affected Products (1)

fuyanglipengjun/wetong_mall

Timeline

Published Jan 12, 2024
Tracked Since Feb 18, 2026