ID EDB-ID-50142
CVSS 3.0 9.1
Cloudbric Score
Cloudbric Detection Yes
Vulnerability Type SQL Injection
Published Date 2021-07-19
Updated Date 2021-09-10
Vendor 9.3.0
Description PEEL Shopping is an eCommerce shopping cart application in PHP / MySQL which works on any hosting. Public user/guest (unauthenticated) can inject malicious SQL query in order to affect the execution of predefined SQL commands via the "id" parameter on the "/peel-shopping_9_4_0/achat/produit_details.php?id=[SQLi]" endpoint. Upon successful of SQL injection attack, attacker can read sensitive data from the database or modify database data.
