SQL Injection Vulnerability in Kashipara Ecommerce Website by Kashipara
CVE-2024-44651

6.5MEDIUM

Key Information:

Vendor

Kashipara

Vendor
CVE Published:
17 November 2025

What is CVE-2024-44651?

The Kashipara Ecommerce Website version 1.0 is exposed to a SQL Injection vulnerability through the 'recover_email' parameter in the user_password_recover.php file. This issue allows an attacker to manipulate SQL queries, potentially gaining unauthorized access to sensitive data and compromising the security of the web application. Prompt mitigation is required to address this risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.