SQL Injection Vulnerability in ECShop 3.0 by ECShop
CVE-2020-22206
9.8CRITICAL
What is CVE-2020-22206?
A SQL injection vulnerability exists in ECShop 3.0 that allows attackers to manipulate SQL queries through the 'aid' parameter in admin/affiliate_ck.php. This flaw can enable unauthorized access to sensitive data and administrative functions, potentially compromising the entire application. It is crucial for users of ECShop 3.0 to apply necessary security measures to mitigate risks associated with this vulnerability.
