VendorsNiushopb2b2c_multi-businessall versions
Vulnerabilities

Niushop B2B2C Multi-Business

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-25247
SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.
Published 2024-02-26 · Analyzed
9.8EPSS 0.006
CVE-2024-25248
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
Published 2024-02-26 · Modified
9.8EPSS 0.006
CVE-2024-0933
Niushop B2B2C Upload.php unrestricted upload
Published 2024-01-26 · Modified
9.8EPSS 0.006
CVE-2018-14570
A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to upload a .php file to the web server via a profile avatar field, by using an image Content-Type (e.g., image/jpeg) with a modified filename and file content. This results in arbitrary code execution by requesting that .php file.
Published 2018-07-23 · Modified
8.8EPSS 0.018
CVE-2024-28559
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.
Published 2024-03-22 · Analyzed
8.8EPSS 0.008
CVE-2024-28560
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.
Published 2024-03-22 · Analyzed
5.4EPSS 0.005