KomSeo Cart 1.3 SQL Injection via edit.php
Vulnerability Description
KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to extract sensitive database information using boolean-based blind or error-based injection techniques.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25206
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Özkan Mustafa Akkuş (AkkuS)
Affected Vendor
Sitemakin
View all reports →