Back to Database
Status published
Critical
CVE-2019-19113
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword=...
Vulnerability Description
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19113
Credits & Attribution
No credits recorded in the NVD database.
More from newbee-mall project
View All →CVE-2022-27477
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload...
Critical
9.8
CVE-2022-27476
A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0...
Medium
6.1
CVE-2020-23449
newbee-mall all versions are affected by incorrect access control to...
High
7.5
CVE-2020-23448
newbee-mall all versions are affected by incorrect access control to...
Critical
9.8
CVE-2020-23447
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users...
Medium
6.1
Affected Vendor
newbee-mall project
View all reports →Affected Software
newbee-mall
Vulnerable Versions:
0
Timeline
Official Publish:
November 18th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.