Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3h9-m7wg-g7rh

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.

SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.

EPSS

Процентиль: 66%
0.00506
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
больше 8 лет назад

SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.

EPSS

Процентиль: 66%
0.00506
Низкий

7.2 High

CVSS3

Дефекты

CWE-89