SQL Injection Vulnerability in CodeAstro Ecommerce Site Search Component
CVE-2024-2351
Key Information:
- Vendor
Codeastro
- Status
- Vendor
- CVE Published:
- 9 March 2024
Badges
What is CVE-2024-2351?
A vulnerability within the CodeAstro Ecommerce Site’s Search functionality has been identified, specifically in the action.php file. This flaw allows for SQL injection through manipulation of the parameters cat_id, brand_id, or keyword. Attackers can exploit this vulnerability remotely, potentially compromising database integrity and data confidentiality. The exploit has been made public, increasing the risk of attacks leveraging this vulnerability. Users of affected versions should promptly apply patches or workarounds to secure their systems against potential exploitation.
Affected Version(s)
Ecommerce Site 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved