CVE-2020-22205: SQL Injection
Published Jun 16, 2021
·Updated
SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
Affected Software
1 affected component
shopex ecshop=3.0
Event History
Jun 16, 2021
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22205?
CVE-2020-22205 is a vulnerability that allows an attacker to perform SQL injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
2
How severe is CVE-2020-22205?
CVE-2020-22205 has a severity rating of 9.8, which is considered critical.
3
Which software version is affected by CVE-2020-22205?
The vulnerability affects ECShop version 3.0.
4
How can I fix CVE-2020-22205?
To fix CVE-2020-22205, update ECShop to a version that is not affected by the vulnerability.
5
Is there any reference material available for CVE-2020-22205?
Yes, you can find reference material for CVE-2020-22205 at this link: https://github.com/blindkey/cve_like/issues/8