CVE-2024-28559
HIGHNiushop B2B2C < 5.3.3 - SQL Injection via Goodsbatchset.php setPrice() Function
Title source: llmDescription
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.
References (5)
Core 5
Core References
Exploit, Third Party Advisory
https://chiggerlor.substack.com/p/cve-2024-28560-cve-2024-28559
Permissions Required
https://gitee.com/niushop-team/niushop_b2c_v5
Broken Link
https://v5.niuteam.cn
Broken Link
https://v5.niuteam.cn/
Vendor Advisory
https://www.niushop.com/
Scores
CVSS v3
8.8
EPSS
0.0058
EPSS Percentile
69.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
niushop/b2b2c_multi-business
< 5.3.3
Published
Mar 22, 2024
Tracked Since
Feb 18, 2026