CVE-2020-22206: SQL Injection
Published Jun 16, 2021
·Updated
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliateck.php.
Affected Software
1 affected component
shopex ecshop=3.0
Event History
Jun 16, 2021
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22206?
CVE-2020-22206 is a vulnerability in ECShop 3.0 that allows for SQL Injection via the aid parameter in admin/affiliate_ck.php.
2
How severe is CVE-2020-22206?
CVE-2020-22206 has a severity level of critical, with a CVSS score of 9.8.
3
How does CVE-2020-22206 affect ECShop?
CVE-2020-22206 affects ECShop 3.0 and allows an attacker to exploit the aid parameter in admin/affiliate_ck.php for SQL Injection.
4
What is the affected software version of CVE-2020-22206?
ECShop 3.0 is the affected software version for CVE-2020-22206.
5
Is there a fix for CVE-2020-22206?
Yes, applying the latest security patches and updates for ECShop 3.0 can help mitigate the SQL Injection vulnerability in admin/affiliate_ck.php.