Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) allows SQL Injection. This issue affects WooCommerce Point Of Sale (POS): from n/a through 1.4.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version
Credits
Nguyen Kim Sang (HPT Vietnam) (Patchstack Alliance)
References
patchstack.com/...-1-4-sql-injection-vulnerability?_s_id=cve