SQL Injection Vulnerability in /app/api/controller/Store.php Allows Arbitrary SQL Commands via Latitude and Longitude Parameters
CVE-2024-25247

Currently unrated

Key Information:

Vendor

Niushop

Vendor
CVE Published:
26 February 2024

What is CVE-2024-25247?

SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.