7.5
CVSSv2

CVE-2022-28888

Published: 13/07/2022 Updated: 09/05/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Spryker Commerce OS 1.4.2 allows Remote Command Execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spryker cloud commerce

Exploits

An SQL injection vulnerability affecting Spryker-based webshops was discovered in the order history search form It can be exploited by authenticated attackers in order to retrieve information from the database (eg customer and administrator login information, order details, etc) Depending on the configuration of the webshop, access to the file ...
Spryker Commerce OS with spryker/http module versions prior to 170 suffer from a remote command execution vulnerability due to a predictable value in use ...