Vulnerability CVE-2024-25248


Published: 2024-02-26

Description:
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.

 References:
https://harryha.substack.com/p/phuong-phap-phan-tich-ma-nguon-tim-lo-hong

Copyright 2026, cxsecurity.com

 

Back to Top