The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @evershop/evershop to version 2.1.1 or higher.
@evershop/evershop is a The React Ecommerce platform. Built with React and Postgres. Open-source and free. Fast and customizable.
Affected versions of this package are vulnerable to SQL Injection via the category value used for update and delete operations. It is input to the execute() function without parameterization as part of url_key. An attacker can execute SQL commands by storing a malicious string in the url_key field, which is later processed and executed by the application.