CVE-2024-2074 | Mini-Tmall up to 20231017 ?r=tmall/admin/user/1/1 orderBy sql injection
A vulnerability classified as critical was found in Mini-Tmall up to 20231017. Affected by this issue is some unknown functionality of the file ?r=tmall/admin/user/1/1. Executing a manipulation of the argument orderBy can lead to sql injection.
This vulnerability appears as CVE-2024-2074. The attack may be performed from remote. In addition, an exploit is available.