PT-2021-10748 · Ecshop · Ecshop

Blindkey

·

Published

2021-06-16

·

Updated

2021-06-21

·

CVE-2020-22206

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ECShop version 3.0
Description The issue is related to SQL injection in ECShop 3.0, specifically via the aid parameter to the "admin/affiliate ck.php" endpoint. This allows for potential SQL injection attacks.
Recommendations For ECShop version 3.0, consider restricting access to the "admin/affiliate ck.php" endpoint until a patch is available. As a temporary workaround, avoid using the aid parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-22206

Affected Products

Ecshop