PT-2021-21877 · Unknown · Online Shopping Portal

CVE-2021-37807

·

Published

2021-10-27

·

Updated

2023-11-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Online Shopping Portal version 3.1
Description: A security issue exists in the Online Shopping Portal, specifically an SQL Injection flaw. This issue is present in the email parameter on the "/check availability.php" endpoint, which checks if a new user's email already exists in the database.
Recommendations: For version 3.1, consider restricting access to the /check availability.php endpoint until a patch is available, and avoid using the email parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37807

Affected Products

Online Shopping Portal