The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.exploit-db.com/exploits/50939 |
|
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
T-soft
T-soft e-commerce |
|
| CPEs | cpe:2.3:a:t-soft:e-commerce:*:*:*:*:*:*:*:* | |
| Vendors & Products |
T-soft
T-soft e-commerce |
|
| Metrics |
ssvc
|
Fri, 23 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-05-14T20:20:37.565Z
Updated: 2025-02-13T15:46:22.586Z
Reserved: 2022-03-29T00:00:00.000Z
Link: CVE-2022-28132
Updated: 2024-08-03T05:48:37.880Z
Status : Awaiting Analysis
Published: 2024-05-14T21:15:11.760
Modified: 2024-11-21T06:56:48.713
Link: CVE-2022-28132
No data.