8.8
CVSSv3

CVE-2023-27568

Published: 04/05/2023 Updated: 10/05/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spryker commerce os 0.9

Exploits

An SQL injection vulnerability affecting Spryker-based webshops was discovered in the order history search form It can be exploited by authenticated attackers in order to retrieve information from the database (eg customer and administrator login information, order details, etc) Depending on the configuration of the webshop, access to the file ...