SQL Injection Vulnerability in Kashipara Online Furniture Shopping Ecommerce Website
CVE-2024-4070
What is CVE-2024-4070?
A critical SQL injection vulnerability has been identified within the Kashipara Online Furniture Shopping Ecommerce Website, specifically affecting version 1.0 of the software. This vulnerability originates from improper handling of user input in the 'prodList.php' file, where crafted arguments related to 'prodType' enable an attacker to execute arbitrary SQL commands remotely. The exploitation of this vulnerability can lead to unauthorized access to sensitive data and potential compromise of the database integrity. Security professionals and users of this application are urged to take immediate actions to mitigate risks associated with this vulnerability, particularly since it has been disclosed publicly and can be exploited easily.
Affected Version(s)
Online Furniture Shopping Ecommerce Website 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved