vendor:
T-Soft E-Commerce
by:
Alperen Ergel
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: T-Soft E-Commerce
Affected Version From: v4
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2022-28132
CPE:
Platforms Tested: Kali Linux
2022
T-Soft E-Commerce 4 – SQLi (Authenticated)
Authenticated SQL injection vulnerability in T-Soft E-Commerce 4 allows remote attackers to execute arbitrary SQL commands and gain unauthorized access to the database. The vulnerability can be exploited by an attacker who is logged in as an admin or privileged user.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and use parameterized queries or prepared statements to prevent SQL injection attacks. Regularly updating the software to the latest version and applying security patches is also advised.