Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmcx-2353-j242

Опубликовано: 23 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

EPSS

Процентиль: 15%
0.00237
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
15 дней назад

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

EPSS

Процентиль: 15%
0.00237
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89