SQL Injection Vulnerability in Kashipara Ecommerce Website by Kashipara
CVE-2024-44651
6.5MEDIUM
What is CVE-2024-44651?
The Kashipara Ecommerce Website version 1.0 is exposed to a SQL Injection vulnerability through the 'recover_email' parameter in the user_password_recover.php file. This issue allows an attacker to manipulate SQL queries, potentially gaining unauthorized access to sensitive data and compromising the security of the web application. Prompt mitigation is required to address this risk.
