NA

CVE-2024-34949

Published: 20/05/2024 Updated: 30/05/2024

Vulnerability Summary

SQL injection vulnerability in Likeshop prior to 2.5.7 allows malicious users to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.