CVE-2024-25248
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
More information : https://harryha.substack.com/p/phuong-phap-phan-tich-ma-nguon-tim-lo-hong