VulnerabilityAnalyzed
CVE-2024-28560
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.
MEDIUM 5.4EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- niushop/b2b2c multi-business
- Source
- cve@mitre.org
References
- https://chiggerlor.substack.com/p/cve-2024-28560-cve-2024-28559Exploit, Third Party Advisory
- https://gitee.com/niushop-team/niushop_b2c_v5Permissions Required
- https://v5.niuteam.cnBroken Link
- https://www.niushop.com/Vendor Advisory
- https://chiggerlor.substack.com/p/cve-2024-28560-cve-2024-28559Exploit, Third Party Advisory
- https://gitee.com/niushop-team/niushop_b2c_v5Permissions Required
- https://v5.niuteam.cnBroken Link
- https://www.niushop.com/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.