WordPress 的“Shopping Cart & eCommerce Store”插件存在通用型 SQL 注入漏洞。该漏洞影响所有 5.9.2 及更早版本(含 5.9.2),原因是对用户输入的参数( )缺少充分的转义处理,且现有的 SQL 查询未进行足够的预处理。 这使得拥有管理员及以上权限的已认证攻击者能够将额外的 SQL 查询附加到现有查询中,从而从数据库中提取敏感信息。 这是一个二阶 SQL 注入漏洞:攻击载荷通过 处理程序写入 表(该处理程序未对原始 值进行任何净化处理),随后在每个商店页面渲染时,数
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| levelfourstorefront | Shopping Cart & eCommerce Store | 0 ~ 5.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet