Vulnerabilities > TP Shop > TP Shop > 2.0.8

DATE CVE VULNERABILITY TITLE RISK
2021-08-17 CVE-2020-18164 SQL Injection vulnerability in Tp-Shop 2.0.5/2.0.8
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
network
low complexity
tp-shop CWE-89
7.5