CVE-2024-4071

A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This issue affects some unknown processing of the file prodInfo.php. The manipulation of the argument prodId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261797 was assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aditya88:online_furniture_shopping_ecommerce_website:1.0:*:*:*:*:*:*:*

History

30 Apr 2024, 20:37

Type Values Removed Values Added
CPE cpe:2.3:a:kashipara:online_furniture_shopping_ecommerce_website:1.0:*:*:*:*:*:*:* cpe:2.3:a:aditya88:online_furniture_shopping_ecommerce_website:1.0:*:*:*:*:*:*:*
First Time Aditya88 online Furniture Shopping Ecommerce Website
Aditya88

30 Apr 2024, 20:23

Type Values Removed Values Added
First Time Kashipara online Furniture Shopping Ecommerce Website
Kashipara
CVSS v2 : 6.5
v3 : 6.3
v2 : 6.5
v3 : 8.8
CPE cpe:2.3:a:kashipara:online_furniture_shopping_ecommerce_website:1.0:*:*:*:*:*:*:*
References () https://github.com/E1CHO/cve_hub/blob/main/Online%20Furniture%20Shopping%20Ecommerce%20Website/Online%20Furniture%20Shopping%20Ecommerce%20Website%20Project%20-%20vuln%203.pdf - () https://github.com/E1CHO/cve_hub/blob/main/Online%20Furniture%20Shopping%20Ecommerce%20Website/Online%20Furniture%20Shopping%20Ecommerce%20Website%20Project%20-%20vuln%203.pdf - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.261797 - () https://vuldb.com/?ctiid.261797 - Third Party Advisory
References () https://vuldb.com/?id.261797 - () https://vuldb.com/?id.261797 - Third Party Advisory
References () https://vuldb.com/?submit.321445 - () https://vuldb.com/?submit.321445 - Exploit, Third Party Advisory

24 Apr 2024, 13:39

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue encontrada en Kashipara Online Furniture Shopping Ecommerce Website 1.0 y clasificada como crítica. Este problema afecta un procesamiento desconocido del archivo prodInfo.php. La manipulación del argumento prodId conduce a la inyección de SQL. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-261797.

23 Apr 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-23 22:15

Updated : 2024-05-17 02:40


NVD link : CVE-2024-4071

Mitre link : CVE-2024-4071

CVE.ORG link : CVE-2024-4071


JSON object : View

Products Affected

aditya88

  • online_furniture_shopping_ecommerce_website
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')