VendorsNiushopb2b2c_multi-business5.0
Vulnerabilities

Niushop B2B2C Multi-Business 5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-25247
SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.
Published 2024-02-26 · Analyzed
9.8EPSS 0.006
CVE-2024-25248
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
Published 2024-02-26 · Modified
9.8EPSS 0.006
CVE-2024-0933
Niushop B2B2C Upload.php unrestricted upload
Published 2024-01-26 · Modified
9.8EPSS 0.006