CVE-2021-43679: SQL Injection
Published Dec 2, 2021
·Updated
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
Affected Software
1 affected component
shopex ecshop=2.7.3
Event History
Dec 2, 2021
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-43679?
CVE-2021-43679 is a SQL injection vulnerability in ecshop v2.7.3.
2
How does CVE-2021-43679 affect ecshop v2.7.3?
CVE-2021-43679 allows attackers to perform SQL injection attacks on the affected ecshop v2.7.3 software.
3
What is the severity of CVE-2021-43679?
CVE-2021-43679 has a severity rating of 9.8 (Critical).
4
How can I fix CVE-2021-43679?
To fix CVE-2021-43679, users should update ecshop to a version that is not affected by the vulnerability or apply patches provided by the vendor.
5
Where can I find more information about CVE-2021-43679?
You can find more information about CVE-2021-43679 at the following reference: [CVE-2021-43679](https://github.com/shopex/ecshop/issues/4)