SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
History

Thu, 20 Feb 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Welcart
Welcart welcart E-commerce
CPEs cpe:2.3:a:collne:welcart_e-commerce:*:*:*:*:*:wordpress:*:* cpe:2.3:a:welcart:welcart_e-commerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Collne
Collne welcart E-commerce
Welcart
Welcart welcart E-commerce

Tue, 24 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-09-24T14:28:26.043Z

Reserved: 2023-09-20T04:37:58.491Z

Link: CVE-2023-43610

cve-icon Vulnrichment

Updated: 2024-08-02T19:44:43.847Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T15:19:34.217

Modified: 2025-02-20T18:34:50.990

Link: CVE-2023-43610

cve-icon Redhat

No data.