First published: Tue Sep 26 2023(Updated: )
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Collne Welcart | >=2.7<=2.8.21 | |
Welcart Plugin | >=2.7<=2.8.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability in Welcart e-Commerce is CVE-2023-43610.
The severity of the SQL injection vulnerability in Welcart e-Commerce is high with a severity value of 8.8.
Welcart e-Commerce versions 2.7 to 2.8.21 are affected by this SQL injection vulnerability.
A user with editor or higher privilege can perform unintended database operations through this vulnerability.
To fix this SQL injection vulnerability, update Welcart e-Commerce to a version later than 2.8.21.