Loading vulnerability details…
CVSS v3.1
5.4
EPSS
0.46%
Published
Mar 22, 2024
Modified
May 28, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NWeaknesses (CWE)
Affected Products (1)
References (8)