PT-2022-11461 · Unknown · Peel Shopping Cms
Frentzen
·
Published
2022-06-15
·
Updated
2022-06-23
·
CVE-2021-41672
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PEEL Shopping CMS version 9.4.0
Description
The issue allows for authenticated SQL injection in the utilisateurs.php file. A user belonging to the administrator group can inject a malicious SQL query to affect the application's execution logic and retrieve information from the database.
Recommendations
For PEEL Shopping CMS version 9.4.0, consider restricting access to the utilisateurs.php file until a patch is available. As a temporary workaround, limit the privileges of administrator group users to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peel Shopping Cms