CVE-2023-43493: SQL Injection
Published Sep 26, 2023
·Updated
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress>=2.7<=2.8.21
Welcart Welcart e-Commerce WordPress>=2.7<=2.8.21
Event History
Sep 26, 2023
CVE Published
via MITRE·08:18 AM
Data Sourced
via MITRE·08:18 AM
DescriptionWeakness
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability?
The vulnerability ID for this SQL injection vulnerability is CVE-2023-43493.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Welcart e-Commerce versions 2.7 to 2.8.21.
3
What is the severity of CVE-2023-43493?
The severity of CVE-2023-43493 is medium (4.9).
4
How can a user exploit this vulnerability?
A user with author or higher privilege can exploit this vulnerability to obtain sensitive information.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [JVN97197972](https://jvn.jp/en/jp/JVN97197972/) and [Welcart blog](https://www.welcart.com/archives/20106.html).