SQL Injection Vulnerability in OrderGoodsDelivery() Function
CVE-2024-25248
9.8CRITICAL
What is CVE-2024-25248?
An SQL Injection vulnerability exists in the orderGoodsDelivery() function of Niushop B2B2C V5. This weakness allows attackers to execute arbitrary SQL commands by exploiting the order_id parameter. When improperly validated, this parameter can lead to unauthorized database access and manipulation, posing significant risks to data integrity and confidentiality.