PT-2022-12571 · Unknown · Online Shopping Portal

Published

2022-02-18

·

Updated

2023-11-14

·

CVE-2021-46110

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Shopping Portal version 3.1
Description The issue concerns multiple time-based SQL injection vulnerabilities. These vulnerabilities can be exploited via the email and contactno parameters.
Recommendations For Online Shopping Portal version 3.1, consider restricting access to the affected parameters email and contactno to minimize the risk of exploitation until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-46110

Affected Products

Online Shopping Portal