CVE-2022-4961

MEDIUM

Weitong Mall 1.0.0 - SQL Injection via OrderDao.xml sidx/order Parameter

Title source: llm
STIX 2.1

Description

A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file platform-shop\src\main\resources\com\platform\dao\OrderDao.xml. The manipulation of the argument sidx/order leads to sql injection. The associated identifier of this vulnerability is VDB-250243.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.250243
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.250243
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://gitee.com/fuyang_lipengjun/platform/issues/I5XC79

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 22.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
fuyanglipengjun/wetong_mall 1.0.0
Published Jan 12, 2024
Tracked Since Feb 18, 2026