shopwind 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
公開された問題は vendor risk cross-site scripting、パス処理の欠陥, and vendor risk sql injection に関連することが多く、vendor surface production workloads and vendor surface software deployment の文脈で vendor impact session compromise and vendor impact data exposure などの暴露リスクを伴う場合があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2024-1705 | A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php of the component Installation. The manipulation leads to code injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-254393 was assigned to this vulner | [email protected] | 5.6 | 0.59% | 2024-02-21 | 2025-02-12 |
| CVE-2022-43321 | Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php. | [email protected] | 6.1 | 0.41% | 2022-11-09 | 2025-05-01 |
| CVE-2022-30453 | ShopWind <= 3.4.2 has a RCE vulnerability in Database.php | [email protected] | 9.8 | 14.47% | 2022-05-11 | 2024-11-21 |
| CVE-2022-30452 | ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php | [email protected] | 7.2 | 0.95% | 2022-05-11 | 2024-11-21 |
| CVE-2022-30059 | Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php. | [email protected] | 6.5 | 1.10% | 2022-05-11 | 2024-11-21 |
| CVE-2022-30058 | Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.php. | [email protected] | 5.3 | 1.08% | 2022-05-11 | 2024-11-21 |
| CVE-2022-30057 | Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability. | [email protected] | 5.4 | 0.47% | 2022-05-11 | 2024-11-21 |