PT-2020-7709 · Unknown · Loaded Commerce
Breakingtech
·
Published
2020-01-03
·
Updated
2020-01-14
·
CVE-2014-5140
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Loaded Commerce version 7
Description
The issue concerns the bindReplace function in the query factory, which fails to properly handle colon characters. This allows remote authenticated users to conduct SQL injection attacks through the First name and Last name fields in the address book.
Recommendations
For Loaded Commerce version 7, consider restricting access to the address book fields until a proper fix is applied, and ensure that user input is thoroughly sanitized to prevent SQL injection attacks. As a temporary workaround, consider disabling the bindReplace function in the query factory until a patch is available.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loaded Commerce