Joomla Easy Store extension 1.0.0-2.0.1 contains an unauthenticated SQL injection caused by improper validation of order parameters, letting unauthenticated attackers read the full database including credentials and sessions.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view