SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter ” offerta.php”
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23978
Reference (s):
- https://cxsecurity.com/issue/WLB-2020030150
- https://packetstormsecurity.com/files/156939/Soluzione-Globale-Ecommerce-CMS-1-SQL-Injection.html