First published: Fri Oct 28 2022(Updated: )
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sem-cms | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38732 is a vulnerability in SEMCMS SHOP v 1.1 that allows SQL injection via Ant_Message.php.
CVE-2021-38732 has a severity rating of critical, with a CVSS score of 9.8.
CVE-2021-38732 affects SEMCMS SHOP v 1.1 by enabling SQL injection attacks through the Ant_Message.php file.
To fix CVE-2021-38732, it is recommended to update SEMCMS SHOP to a patched version or apply a security patch provided by the vendor.
More information about CVE-2021-38732 can be found at the following references: [link1](https://github.com/BigTiger2020/SCSHOP/blob/main/semcms-3.md), [link2](https://www.sem-cms.cn/wenda/view-56.html).