Security Advisory

CVE-2024-34949

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-05-20 17:47:50
Last updated 2025-02-13 15:53:44
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.