PT-2025-47169 · Unknown · Kashipara Ecommerce Website

Published

2025-11-17

·

Updated

2025-11-17

·

CVE-2024-44652

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kashipara Ecommerce Website version 1.0
Description The Kashipara Ecommerce Website is susceptible to SQL Injection. The issue affects the user register.php file and involves the user email, username, user firstname, user lastname, and user address parameters. Exploitation of this issue could allow an attacker to manipulate database queries.
Recommendations Apply input validation and sanitization to the user email, username, user firstname, user lastname, and user address parameters in the user register.php file.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-44652

Affected Products

Kashipara Ecommerce Website