Security Advisory

CVE-2024-25248

9.8
CRITICAL

Vulnerability Description

SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
Published Date February 26, 2024
Official Source NIST NVD Advisory