CVE-2024-34949

Publication date

2024-05-20 17:47:50

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.