First published: Thu Oct 31 2024(Updated: )
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Abantecart |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50802 has a high severity rating due to its potential for SQL Injection exploitation.
CVE-2024-50802 affects AbanteCart 1.4.0 by allowing attackers to execute SQL commands through the id parameter.
To fix CVE-2024-50802, update AbanteCart to the latest patched version that addresses this SQL Injection vulnerability.
The attack vector for CVE-2024-50802 is through the id parameter in the update() function in the specified PHP file.
Yes, there are known exploit techniques for CVE-2024-50802 that target the SQL Injection vulnerability in AbanteCart.