CVE-2024-1530: ECshop view_sendlist.php sql injection
Published Feb 15, 2024
·Updated
A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/viewsendlist.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250562 is the identifier assigned to this vulnerability.
Affected Software
1 affected component
shopex ecshop=4.1.8
Event History
Feb 15, 2024
CVE Published
via MITRE·12:46 PM
Data Sourced
via MITRE·12:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 25, 56186
Event
via NVD·07:43 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-1530?
CVE-2024-1530 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2024-1530?
CVE-2024-1530 is an SQL injection vulnerability.
3
How do I fix CVE-2024-1530?
To fix CVE-2024-1530, update your ECshop installation to a patched version that addresses this vulnerability.
4
Can CVE-2024-1530 be exploited remotely?
Yes, CVE-2024-1530 can be exploited remotely.
5
Which version of ECshop is affected by CVE-2024-1530?
CVE-2024-1530 affects ECshop version 4.1.8.