First published: Wed Jun 16 2021(Updated: )
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Shopex Ecshop | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22206 is a vulnerability in ECShop 3.0 that allows for SQL Injection via the aid parameter in admin/affiliate_ck.php.
CVE-2020-22206 has a severity level of critical, with a CVSS score of 9.8.
CVE-2020-22206 affects ECShop 3.0 and allows an attacker to exploit the aid parameter in admin/affiliate_ck.php for SQL Injection.
ECShop 3.0 is the affected software version for CVE-2020-22206.
Yes, applying the latest security patches and updates for ECShop 3.0 can help mitigate the SQL Injection vulnerability in admin/affiliate_ck.php.