PT-2024-20842 · Unknown · Niushop B2B2C

Harry Ha

·

Published

2024-02-26

·

Updated

2024-08-29

·

CVE-2024-25247

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Niushop B2B2C V5 (affected versions not specified)
Description The issue allows attackers to run arbitrary SQL commands via latitude and longitude parameters in the /app/api/controller/Store.php endpoint. This enables potential exploitation for malicious purposes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-25247

Affected Products

Niushop B2B2C