CVE-2022-28132

The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.
Configurations

No configuration.

History

21 Nov 2024, 06:56

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50939 - () https://www.exploit-db.com/exploits/50939 -

23 Aug 2024, 20:35

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

15 May 2024, 16:40

Type Values Removed Values Added
Summary
  • (es) La aplicación web T-Soft E-Commerce 4 es susceptible a ataques de inyección SQL (SQLi) cuando se autentica como administrador o usuario privilegiado. Esta vulnerabilidad permite a los atacantes acceder y manipular la base de datos mediante solicitudes manipuladas. Al explotar esta falla, los atacantes pueden eludir los mecanismos de autenticación, ver información confidencial almacenada en la base de datos y potencialmente filtrar datos.

14 May 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 21:15

Updated : 2024-11-21 06:56


NVD link : CVE-2022-28132

Mitre link : CVE-2022-28132

CVE.ORG link : CVE-2022-28132


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')