PT-2022-11461 · Unknown · Peel Shopping Cms

Frentzen

·

Published

2022-06-15

·

Updated

2022-06-23

·

CVE-2021-41672

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PEEL Shopping CMS version 9.4.0
Description The issue allows for authenticated SQL injection in the utilisateurs.php file. A user belonging to the administrator group can inject a malicious SQL query to affect the application's execution logic and retrieve information from the database.
Recommendations For PEEL Shopping CMS version 9.4.0, consider restricting access to the utilisateurs.php file until a patch is available. As a temporary workaround, limit the privileges of administrator group users to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41672

Affected Products

Peel Shopping Cms