CVE-2023-43610
Welcart e-Commerce <= 2.8.21 - Authenticated(Editor+) SQL Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
Vulnerabilidad de inyección SQL en la página de edición de datos de pedidos de Welcart e-Commerce versiones 2.7 a 2.8.21 permite a un usuario editor (sin autoridad para configurar) o con privilegios superiores realizar operaciones de base de datos no deseadas.
The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the order data edit page in versions up to, and including, 2.8.21 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-09-14 CVE Published
- 2023-09-20 CVE Reserved
- 2024-09-24 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/jp/JVN97197972 | Third Party Advisory | |
https://www.welcart.com/archives/20106.html | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Collne Search vendor "Collne" | Welcart E-commerce Search vendor "Collne" for product "Welcart E-commerce" | >= 2.7 <= 2.8.21 Search vendor "Collne" for product "Welcart E-commerce" and version " >= 2.7 <= 2.8.21" | wordpress |
Affected
|