Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database management system.
Metrics
Affected Vendors & Products
References
History
Sun, 01 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database management system. | |
| Title | Mult-E-Cart Ultimate 2.4 SQL Injection via Vulnerable ID Parameters | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-01T12:15:47.062Z
Reserved: 2026-01-18T12:35:05.177Z
Link: CVE-2021-47909
No data.
Status : Received
Published: 2026-02-01T13:15:54.890
Modified: 2026-02-01T13:15:54.890
Link: CVE-2021-47909
No data.
OpenCVE Enrichment
No data.