vendor:
Aimeos Laravel ecommerce platform
by:
Ilker Burak ADIYAMAN
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Aimeos Laravel ecommerce platform
Affected Version From: Aimeos 2021.10 LTS
Affected Version To: Aimeos 2021.10 LTS
Patch Exists: NO
Related CWE:
CPE: a:aimeos:aimeos_laravel_ecommerce_package
Platforms Tested: MacOSX
2021
Aimeos Laravel ecommerce platform 2021.10 LTS – ‘sort’ SQL injection
The Aimeos E-Commerce framework Laravel application is vulnerable to SQL injection via the 'sort' parameter on the json api.
Mitigation:
Input validation and sanitization should be done on the server side to prevent SQL injection.