header-logo
Suggest Exploit
vendor:
Super Store Finder
by:
bRpsd
6.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Super Store Finder
Affected Version From: 3.7 and below
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: macOS, Linux (xampp)
2023

SuperStoreFinder – Multiple Vulnerabilities

SuperStoreFinder is a PHP/Javascript/MySQL store locator script with Google Maps API integration. A vulnerability exists in the 'USERNAME' parameter in the 'localhost/admin/index.php' file, allowing unauthenticated SQL Injection attacks including boolean-based blind, error-based, and time-based blind attacks.

Mitigation:

To mitigate this vulnerability, sanitize user inputs, implement prepared statements, and validate and encode user-supplied data.
Source

Exploit-DB raw data: