CVE-2024-42404

SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database.
Configurations

No configuration.

History

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de inyección SQL en Welcart e-Commerce anterior a la versión 2.11.2 permite que un atacante que pueda iniciar sesión en el producto obtenga o altere la información almacenada en la base de datos.

18 Sep 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-89

18 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-18 06:15

Updated : 2024-09-20 12:30


NVD link : CVE-2024-42404

Mitre link : CVE-2024-42404

CVE.ORG link : CVE-2024-42404


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')