CVE-2024-25248 Information
Feb 29, 2024
cve
Description
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
Reference
https://harryha.substack.com/p/phuong-phap-phan-tich-ma-nguon-tim-lo-hong
Share on: