ZeroHour

CVE-2024-28559

PoC
CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
Description

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.

Vendors
niushop
Products
b2b2c multi-business
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.