CVE-2021-41460: SQL Injection
Published Jun 28, 2022
·Updated
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
Affected Software
1 affected component
shopex ecshop=4.1.0
Event History
Jun 28, 2022
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
Description
Frequently Asked Questions
1
What is CVE-2021-41460?
CVE-2021-41460 is a SQL injection vulnerability in ECShop 4.1.0, which can be exploited by attackers to obtain sensitive information.
2
What is the severity of CVE-2021-41460?
The severity of CVE-2021-41460 is high, with a severity value of 7.5.
3
How can attackers exploit CVE-2021-41460?
Attackers can exploit CVE-2021-41460 by performing SQL injection attacks to obtain sensitive information.
4
How can I fix CVE-2021-41460?
To fix CVE-2021-41460, it is recommended to update ECShop to a version that includes the security patch for this vulnerability.
5
Where can I find more information about CVE-2021-41460?
You can find more information about CVE-2021-41460 at the following reference: [CVE-2021-41460](https://www.cnvd.org.cn/flaw/show/CNVD-2020-58823).