PT-2025-50744 · Unknown · Xhibiter Nft Marketplace
Sohel Yousef
·
Published
2025-12-11
·
Updated
2026-01-21
·
CVE-2024-58290
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Xhibiter NFT Marketplace version 1.10.2
Description
The Xhibiter NFT Marketplace software has a SQL injection issue in the collections endpoint. An attacker can manipulate database queries by using the
id parameter. Boolean-based, time-based, and UNION-based SQL injection techniques can be used to extract or manipulate database information by sending crafted payloads to the collections page. The API endpoint affected is '/collections'. The vulnerable parameter is id.Recommendations
Apply a fix to sanitize the
id parameter in the collections endpoint to prevent SQL injection. As a temporary workaround, restrict access to the collections endpoint to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xhibiter Nft Marketplace