VendorsShipment 100-design Material Download System Projectshipment_100-design_material_download_systemall versions
Vulnerabilities

Shipment 100-design Material Download System Project Shipment 100-design Material Download System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2021-29350
SQL injection in the getip function in conn/function.php in 发货100-设计素材下载系统 1.1 allows remote attackers to inject arbitrary SQL commands via the X-Forwarded-For header to admin/product_add.php.
Published 2021-04-29 · Modified
7.2EPSS 0.013