PT-2023-4916 · Unknown · Super Store Finder

Published

2023-09-04

·

Updated

2023-09-08

·

CVE-2023-41507

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Super Store Finder version 3.6
Description The issue is related to a lack of protection against SQL query structure exploitation, which can allow a remote attacker to gain access to the administration panel. The store locator component is affected via the products, distance, lat, and lng parameters.
Recommendations For Super Store Finder version 3.6, consider disabling the store locator component until a patch is available to prevent exploitation of the SQL injection vulnerabilities. Restrict access to the administration panel to minimize the risk of unauthorized access. Avoid using the products, distance, lat, and lng parameters in the affected component until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-05423
CVE-2023-41507

Affected Products

Super Store Finder