← Back to browse · API

CVE-2023-25960

Severity
CRITICAL
CVSS
10.0
EPSS
0.0069
Risk score
40.24
CISA KEV
No
PoC
No
Published
2023-11-03
Modified
2026-04-28
First seen
2026-08-07
Aliases
EUVD-2023-29847, GHSA-GWP9-GFC2-VCCQ
Products
Zendrop:Zendrop – Global Dropshipping n/a ≤1.0.0
Sources
euvd EUVD-2023-29847

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.

References