CVE-2022-28132

The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.
Configurations

No configuration.

History

21 Nov 2024, 06:56

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50939 - () https://www.exploit-db.com/exploits/50939 -

23 Aug 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CWE CWE-89

15 May 2024, 16:40

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 21:15

Updated : 2024-11-21 06:56


NVD link : CVE-2022-28132

Mitre link : CVE-2022-28132

CVE.ORG link : CVE-2022-28132


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')