CVE-2018-5973: Eihitech Professional Local Directory Script

Critical severity, CVSS 9.8. EPSS: 20.1% chance of exploitation in the next 30 days.

SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.

Affected products

  • Eihitech Professional Local Directory Script: version 1.0 only

Published 2018-01-25. Last modified 2026-06-17.