PT-2026-5474 · Infor · Infor Storefront B2B
Ratboy
·
Publicado
2026-01-30
·
Atualizado
2026-02-03
·
CVE-2020-37033
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Infor Storefront B2B version 1.0
Description
Infor Storefront B2B version 1.0 contains a SQL injection issue that allows attackers to manipulate database queries. This is achieved through the
usr name parameter within login requests. Attackers can inject malicious SQL code into the usr name parameter, potentially allowing them to extract or modify database information. The vulnerable API endpoint is the login request.Recommendations
Versions prior to 1.0 should be updated.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Infor Storefront B2B