Opencart Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2020-20491 - Vulnerability Database
Opencart Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2020-20491
High
Reference:
CVE-2020-20491
Title:
Opencart Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.