Niushop
Niushop B2b2c Multi-business: vulnerabilidades y CVE
Niushop B2b2c Multi-business tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-28560 | Media (5.4) | 0.46% | — | 22 mar 2024 | SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component. |
| CVE-2024-28559 | Alta (8.8) | 0.81% | — | 22 mar 2024 | SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component. |
| CVE-2024-25247 | Crítica (9.8) | 0.63% | — | 26 feb 2024 | SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters. |
| CVE-2024-25248 | Crítica (9.8) | 0.63% | — | 26 feb 2024 | SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter. |
| CVE-2024-0933 | Crítica (9.8) | 0.58% | — | 26 ene 2024 | A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \app\model\Upload.php. The manipulation leads to unrestricted upload. The attack… |
| CVE-2018-14570 | Alta (8.8) | 1.8% | — | 23 jul 2018 | A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to upload a .php file to the web server via a profile avatar field, by… |