What the vulnerability does
01Description
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
Explanation of Vulnerability in Simple Terms
Persian Woocommerce SMS versions up to 7.2.2 contain a SQL injection vulnerability in database query handling. An attacker with high-level privileges can inject malicious SQL commands to read sensitive data from the site's database. The vulnerability requires administrative or elevated account access to exploit.
What an attacker can do
Read sensitive data from the site's database by injecting SQL commands.
Potential impact on your site
An admin or privileged user account could be compromised to extract customer data, payment info, or other database records.
Conditions required to exploit
Attacker must have high-level privileges (admin or equivalent role) on the site.
Key dates
External resources
Related vulnerabilities