A vulnerability, which was classified as critical, has been found in SUL1SS_shop. This issue affects some unknown processing of the file application\merch\controller\Order.php. The manipulation of the argument keyword leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-222599.
References
Link Resource
https://tib36.github.io/2023/03/04/SUL1SS-shop-SQLi/ Exploit Third Party Advisory
https://vuldb.com/?ctiid.222599 Third Party Advisory
https://vuldb.com/?id.222599 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulDB

Published: 2023-03-08T18:00:40.000Z

Updated: 2024-02-13T07:50:27.728Z

Reserved: 2023-03-08T17:59:59.897Z


Link: CVE-2023-1276

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-03-08T19:15:10.677

Modified: 2024-05-17T02:17:56.020


Link: CVE-2023-1276

JSON object: View

cve-icon Redhat Information

No data.

CWE