What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.
Explanation of Vulnerability in Simple Terms
XStore versions up to 9.3.5 contain a SQL injection vulnerability in an unspecified component. An attacker can craft malicious input to execute arbitrary SQL queries against the site's database without authentication. This can lead to unauthorized data access and potential service disruption. Update to a version newer than 9.3.5 immediately.
What an attacker can do
Execute SQL queries to read or modify the site's database without logging in.
Potential impact on your site
Attackers can steal customer data, admin credentials, and payment information, or disable the site.
Conditions required to exploit
Network access to the vulnerable XStore installation; no authentication required.
Key dates
External resources
Related vulnerabilities