High
CVSS 8.2
Overview
SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.
SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abi...
SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.
This vulnerability is rated 🟠 HIGH.
Recommended actions: