0
CVE-2023-4674
- EPSS 0.26%
- Veröffentlicht 29.12.2023 15:15:09
- Zuletzt bearbeitet 21.05.2026 09:16:24
- Quelle iletisim@usom.gov.tr
- CVE-Watchlists
- Unerledigt
SQLi in Yazteks E-Commerce Software
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection.
This issue affects E-Commerce Software: through 20231229.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yaztekteknoloji ≫ E-commerce SwPlatformwordpress Version <= 20231229
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.175 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
https://www.usom.gov.tr/bildirim/tr-23-0741
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0741