CVE-2017-17624: PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce
Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
Affected products
- PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce: version 1.0 only
Published 2017-12-13. Last modified 2026-06-17.