CVE detail
CVE-2021-29350 — CVE-2021-29350
Published 2021-04-29 · Modified 2026-06-17 · Vendor shipment_100-design_material_download_system_project · Product shipment_100-design_material_download_system · Source nvd
HIGH
severity
CVSS-derived band
0.0131
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
SQL injection in the getip function in conn/function.php in 发货100-设计素材下载系统 1.1 allows remote attackers to inject arbitrary SQL commands via the X-Forwarded-For header to admin/product_add.php.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References