SQL Injection vulnerability in the orderGoodsDelivery()...
Critical severity
Unreviewed
Published
Feb 27, 2024
to the GitHub Advisory Database
•
Updated Feb 14, 2025
Description
Published by the National Vulnerability Database
Feb 26, 2024
Published to the GitHub Advisory Database
Feb 27, 2024
Last updated
Feb 14, 2025
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
References