SQL Injection Vulnerability in E-commerce MLM Software by E-commerce Vendor
CVE-2017-17610

9.8CRITICAL

What is CVE-2017-17610?

E-commerce MLM Software version 1.0 is susceptible to SQL Injection vulnerabilities through the 'pid' parameter in service_detail.php, the 'eventid' parameter in event_detail.php, and the 'newid' parameter in news_detail.php. Exploiting these weaknesses could allow an attacker to execute arbitrary SQL code, potentially leading to unauthorized access to sensitive data and compromising the integrity of the database.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.