CVE-2024-33268

Publication date

2024-04-29 00:00:00

Family

mitre

State

PUBLISHED

Description

SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addGiftToCart method.