Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Shopware SQL注入漏洞
Vulnerability Description
Shopware是德国Shopware公司的一套开源电子商务软件。 Shopware B2B-Suite 4.4.1 及之前版本存在安全漏洞,该漏洞允许经过身份验证的远程攻击者转储底层数据库。
CVSS Information
N/A
Vulnerability Type
N/A