PT-2020-6498 · Ecshop · Ecshop
Blindkey
·
Published
2020-02-18
·
Updated
2021-06-21
·
CVE-2020-22205
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ECShop version 3.0
Description
The issue is related to a lack of measures to neutralize special elements used in SQL queries, which can be exploited by a remote attacker to execute arbitrary SQL code. This can be done by executing the admin/shophelp.php script with the
id parameter.Recommendations
For ECShop version 3.0, consider restricting access to the admin/shophelp.php script or disabling the use of the
id parameter until a patch is available. As a temporary workaround, avoid using the id parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecshop