CVE-2023-38044
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CWE
- CWE-89 — CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected
- hikashop.com / HikaShop component for Joomla — v=4.0.0-4.7.2 [affected]
CVSS
- (none)
References
- https://www.hikashop.com/support/documentation/56-hikashop-changelog.html vendor-advisory
- https://extensions.joomla.org/vulnerable-extensions/resolved/hikashop-versions-from-4-4-1-to-4-7-2-are-affected-sql-injection/ third-party-advisory
Source
cvelistV5-main/cves/2023/38xxx/CVE-2023-38044.json