CVE-2018-25206 describes an SQL injection vulnerability in KomSeo Cart 1.3, allowing attackers to inject SQL commands via the 'my_item_search' parameter in edit.php through POST requests. This flaw enables the extraction of sensitive database information using blind or error-based techniques. With a CVSS v3.1 score of 8.2 (HIGH), it is a remotely exploitable vulnerability requiring no authentication or user interaction, posing a significant risk to confidentiality. However, there is no known exploit code, active exploitation, or community discussion, and its EPSS score indicates a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sitemakin | KomSeo Cart | 1.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.