SQL Injection Vulnerability in ECShop 2.7.6 by ECShop
CVE-2020-22204
9.8CRITICAL
What is CVE-2020-22204?
An SQL Injection vulnerability exists in ECShop version 2.7.6, which can be exploited through the 'goods_number' parameter in the flow.php file. This weakness could allow attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation. It emphasizes the need for rigorous input validation and security measures to protect against exploitation.
