yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Catherines77/79e6b69490b085d9c2d96c99e72c3579 | Third Party Advisory |
| https://github.com/guchengwuyue/yshopmall/issues/34 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/guchengwuyue/yshopmall/issues/34 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-03-04 22:15
Updated : 2025-06-12 20:34
NVD link : CVE-2025-25426
Mitre link : CVE-2025-25426
CVE.ORG link : CVE-2025-25426
JSON object : View
Products Affected
guchengwuyue
- yshopmall
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
