First published: Tue Sep 26 2023(Updated: )
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | >=2.7<=2.8.21 | |
Welcart Plugin | >=2.7<=2.8.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability is CVE-2023-43493.
The affected software for this vulnerability is Welcart e-Commerce versions 2.7 to 2.8.21.
The severity of CVE-2023-43493 is medium (4.9).
A user with author or higher privilege can exploit this vulnerability to obtain sensitive information.
You can find more information about this vulnerability at the following references: [JVN97197972](https://jvn.jp/en/jp/JVN97197972/) and [Welcart blog](https://www.welcart.com/archives/20106.html).