NA

CVE-2023-6579

Published: 07/12/2023 Updated: 11/04/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argument estimate[country_id] leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-247160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oscommerce oscommerce 4.0

Vendor Advisories

Check Point Reference: CPAI-2023-1413 Date Published: 27 Dec 2023 Severity: Critical ...

Exploits

osCommerce version 4 suffers from a remote SQL injection vulnerability ...