PT-2020-14435 · Unknown · Persian Vip Download Script

S3Ffr

·

Published

2020-07-01

·

Updated

2020-07-07

·

CVE-2020-15468

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Persian VIP Download Script version 1.0
Description The issue allows SQL Injection via the active parameter in the "cart edit.php" endpoint.
Recommendations For version 1.0, avoid using the active parameter in the "cart edit.php" endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15468

Affected Products

Persian Vip Download Script