Vulnerability Description
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abantecart | Abantecart | 1.4.0 |
Related Weaknesses (CWE)
References
- https://chiggerlor.substack.com/p/cve-2024-50801-and-and-cve-2024-50802ExploitThird Party Advisory
- https://github.com/abantecart/abantecart-srcProduct
FAQ
What is CVE-2024-50801?
CVE-2024-50801 is a vulnerability with a CVSS score of 6.0 (MEDIUM). A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via t...
How severe is CVE-2024-50801?
CVE-2024-50801 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-50801?
Check the references section above for vendor advisories and patch information. Affected products include: Abantecart Abantecart.