CVE-2024-28559: Niushop b2b2c Multi-Business
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.
Affected products
- Niushop b2b2c Multi-Business: up to and including 5.3.3
Published 2024-03-22. Last modified 2026-06-17.