CVE-2023-5293: ECshop leancloud.php sql injection
A vulnerability, which was classified as critical, was found in ECshop 4.1.5. Affected is an unknown function of the file /admin/leancloud.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240924.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5293?
The severity of CVE-2023-5293 is medium with a severity value of 6.5.
What is the affected software for CVE-2023-5293?
The affected software for CVE-2023-5293 is ECshop 4.1.5.
How does CVE-2023-5293 impact the system?
CVE-2023-5293 allows for remote SQL injection attacks through the manipulation of the id argument in the /admin/leancloud.php file.
Is there a fix available for CVE-2023-5293?
There is no information available about an official fix for CVE-2023-5293 at this time.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-5293?
The Common Weakness Enumeration (CWE) ID for CVE-2023-5293 is CWE-89.