PT-2022-10763 · Unknown · Semcms Shop

Bigtiger2020

·

Published

2022-10-28

·

Updated

2025-05-07

·

CVE-2021-38732

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEMCMS SHOP version 1.1
Description The issue affects the Ant Message.php file, allowing for SQL injection.
Recommendations For SEMCMS SHOP version 1.1, consider restricting access to the Ant Message.php file until a patch is available. As a temporary workaround, avoid using parameters that could lead to SQL injection in the affected file.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-38732

Affected Products

Semcms Shop