PT-2023-4916 · Unknown · Super Store Finder
Published
2023-09-04
·
Updated
2023-09-08
·
CVE-2023-41507
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Super Store Finder version 3.6
Description
The issue is related to a lack of protection against SQL query structure exploitation, which can allow a remote attacker to gain access to the administration panel. The store locator component is affected via the
products, distance, lat, and lng parameters.Recommendations
For Super Store Finder version 3.6, consider disabling the store locator component until a patch is available to prevent exploitation of the SQL injection vulnerabilities. Restrict access to the administration panel to minimize the risk of unauthorized access. Avoid using the
products, distance, lat, and lng parameters in the affected component until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Super Store Finder