← Back

Loaded7

loaded7

Vendor: Loadedcommerce • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Loadedcommerce
1Loaded7
Nov 21, 2024
Jan 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks...Show more
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.Show less