SQL Injection Vulnerability in Webkul Bundle Product by Webkul
CVE-2023-51210
9.8CRITICAL
Summary
An SQL injection vulnerability has been identified in Webkul Bundle Product version 6.0.1, which can be exploited by remote attackers. This vulnerability enables threat actors to inject malicious SQL commands through the id_product parameters within the UpdateProductQuantity function. If successfully executed, this could lead to unauthorized access to sensitive data or arbitrary code execution, posing significant risks to affected systems and user data.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved