CVE-2023-43610: SQL Injection
Published Sep 26, 2023
·Updated
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
Affected Software
2 affected components
Collne Welcart E-commerce Wordpress>=2.7<=2.8.21
Welcart Welcart e-Commerce WordPress>=2.7<=2.8.21
Event History
Sep 26, 2023
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
DescriptionWeakness
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability in Welcart e-Commerce?
The vulnerability ID for this SQL injection vulnerability in Welcart e-Commerce is CVE-2023-43610.
2
What is the severity of the SQL injection vulnerability in Welcart e-Commerce?
The severity of the SQL injection vulnerability in Welcart e-Commerce is high with a severity value of 8.8.
3
Which versions of Welcart e-Commerce are affected by this SQL injection vulnerability?
Welcart e-Commerce versions 2.7 to 2.8.21 are affected by this SQL injection vulnerability.
4
What can a user with editor or higher privilege do through this vulnerability?
A user with editor or higher privilege can perform unintended database operations through this vulnerability.
5
How can I fix this SQL injection vulnerability in Welcart e-Commerce?
To fix this SQL injection vulnerability, update Welcart e-Commerce to a version later than 2.8.21.