SQL Injection Vulnerability in Smartshop 1 by Smartshop
CVE-2018-25342
Key Information:
Badges
What is CVE-2018-25342?
Smartshop 1 is susceptible to a time-based blind SQL injection that enables unauthenticated attackers to manipulate database queries. By injecting malicious SQL code through the 'searched' parameter in search.php, attackers can execute crafted GET requests to the application. This may lead to the extraction of sensitive information from the database, including critical product details and system data, posing significant risks to user data and application integrity.
Affected Version(s)
Smartshop 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
