В исходном коде Online Medicine Delivery System 1.0 обнаружена уязвимость безопасности. Эта проблема касается функции loadResultList файла /index.php?q=single-item страницы сведений о продукте компонента. Такая манипуляция идентификатором аргумента приводит к SQL-инъекции.
Атака может быть запущена удаленно. Эксплойт был раскрыт публично и может быть использован.
Показать оригинальное описание (EN)
A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item of the component Product Detail Page. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Характеристики атаки
Последствия
Строка CVSS v4.0