Skip to content

Blind SQLi in Catalog Product edition

High
PierreRambaud published GHSA-fghq-8h87-826g Sep 24, 2020

Package

No package listed

Affected versions

>= 1.7.5.0

Patched versions

1.7.6.8

Description

Impact

Blind SQLi in the Catalog Product edition page with location parameter.

Patches

The problem is fixed in 1.7.6.8

References

SQL Injection (CWE-89)

Severity

High

CVE ID

CVE-2020-15160

Weaknesses

No CWEs

Credits