What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Collne Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Collne Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.3.
Explanation of Vulnerability in Simple Terms
Welcart e-Commerce versions up to 2.9.3 contain a SQL injection vulnerability accessible to high-privilege users. An attacker with administrative or elevated access can craft malicious input to execute arbitrary SQL queries, potentially reading sensitive database records. The vulnerability affects confidentiality and availability but not data integrity.
What an attacker can do
Read sensitive data from the database or degrade site performance through SQL injection.
Potential impact on your site
High-privilege accounts could be compromised to extract customer data, orders, or payment information from your database.
Conditions required to exploit
Attacker must have high-privilege account access (admin or equivalent role).
Key dates
External resources
Related vulnerabilities