PT-2026-5474 · Infor · Infor Storefront B2B
Ratboy
·
Published
2026-01-30
·
Updated
2026-02-03
·
CVE-2020-37033
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Infor Storefront B2B version 1.0
Description
Infor Storefront B2B version 1.0 contains a SQL injection issue that allows attackers to manipulate database queries. This is achieved through the
usr name parameter within login requests. Attackers can inject malicious SQL code into the usr name parameter, potentially allowing them to extract or modify database information. The vulnerable API endpoint is the login request.Recommendations
Versions prior to 1.0 should be updated.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infor Storefront B2B