PT-2026-5474 · Infor · Infor Storefront B2B

Ratboy

·

Published

2026-01-30

·

Updated

2026-02-03

·

CVE-2020-37033

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Infor Storefront B2B version 1.0
Description Infor Storefront B2B version 1.0 contains a SQL injection issue that allows attackers to manipulate database queries. This is achieved through the usr name parameter within login requests. Attackers can inject malicious SQL code into the usr name parameter, potentially allowing them to extract or modify database information. The vulnerable API endpoint is the login request.
Recommendations Versions prior to 1.0 should be updated.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-37033

Affected Products

Infor Storefront B2B