First published: Thu Dec 02 2021(Updated: )
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Shopex Ecshop | =2.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43679 is a SQL injection vulnerability in ecshop v2.7.3.
CVE-2021-43679 allows attackers to perform SQL injection attacks on the affected ecshop v2.7.3 software.
CVE-2021-43679 has a severity rating of 9.8 (Critical).
To fix CVE-2021-43679, users should update ecshop to a version that is not affected by the vulnerability or apply patches provided by the vendor.
You can find more information about CVE-2021-43679 at the following reference: [CVE-2021-43679](https://github.com/shopex/ecshop/issues/4)