CNNVD-202512-2064 Information

CNNVD ID

CNNVD-202512-2064

CVE-2024-58290

  • CNNVD Published: 2025-12-11

Description (Chinese)

DeoThemes Xhibiter NFT Marketplace是DeoThemes公司的一个建站工具。 DeoThemes Xhibiter NFT Marketplace 1.10.2版本存在SQL注入漏洞,该漏洞源于collections端点中id参数存在SQL注入,可能导致数据库信息泄露或篡改。

Description (English)

DeoThemes Xhibiter NFT Marketplace is a building tool for DeoThemes. DeoThemes Xhibiter NFT Marketplace version 1.10.2 has an injection loophole in SQL, which stems from the presence of SQL input of id parameters in the endpoint of Collactions, which may lead to the leaking or tampering of database information.

Hazard Level

High

Vulnerability Type

SQL注入

Affected Vendor

DeoThemes

Published

2025-12-11

Last Modified

2026-02-24

References

https://elements.envato.com/xhibiter-nft-marketplace-html-template-AQN45FA https://www.exploit-db.com/exploits/52060 https://www.vulncheck.com/advisories/xhibiter-nft-marketplace-sql-injection-via-collections-endpoint

Patch

https://elements.envato.com/xhibiter-nft-marketplace-html-template-AQN45FA

Share on: