ID

VAR-202004-2255


TITLE

There is a SQL injection vulnerability in the or***.php file of Jinwei Mobile Store

Trust: 0.6

sources: CNVD: CNVD-2020-23561

DESCRIPTION

The Jinwei mobile shopping mall system is suitable for Wechat customers with a public account. It imitates the layout of the page and supports embedded video playback. Support custom model specifications, main specifications support accompanying pictures, each subdivision model supports inventory control, subdivision models can set different prices. There is a SQL injection vulnerability in the or***.php file of the Jinwei mobile shopping mall system. Attackers can use vulnerabilities to obtain sensitive database information.

Trust: 0.6

sources: CNVD: CNVD-2020-23561

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-23561

AFFECTED PRODUCTS

vendor:hubei taoma qianwei informationmodel:jinwei mobile shopping systemscope:eqversion:v0.2.5

Trust: 0.6

sources: CNVD: CNVD-2020-23561

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-23561
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2020-23561
severity: MEDIUM
baseScore: 4.9
vectorString: AV:N/AC:H/AU:S/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-23561

PATCH

title:There is a SQL injection vulnerability in order.php of version 0.2.4 of the Jinwei mobile shopping mall systemurl:https://www.cnvd.org.cn/patchinfo/show/208825

Trust: 0.6

sources: CNVD: CNVD-2020-23561

EXTERNAL IDS

db:CNVDid:CNVD-2020-23561

Trust: 0.6

sources: CNVD: CNVD-2020-23561

SOURCES

db:CNVDid:CNVD-2020-23561

LAST UPDATE DATE

2022-05-04T09:28:10.141000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-23561date:2020-04-24T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-23561date:2020-04-27T00:00:00