Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-39560 | ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php. ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2022-25098 | ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter. ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter. NVD description · AI analysis pending | 9.1 | <1% |
| — | ||
| CVE-2020-21806 | SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php.. SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php.. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2020-18144 | SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php. SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |