CVE-2021-41672

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
15/06/2022
Last modified:
23/06/2022

Description

PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:peel:peel_shopping:9.4.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools