CVE-2024-42404: Welcart E-Commerce
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database.
Affected products
- Welcart Welcart E-Commerce: before 2.11.2 (fixed in 2.11.2)
Published 2024-09-18. Last modified 2026-06-17.