_checkValForAPI of the file htdocs/expedition/class/expedition.class.php of the component Shipments API Endpoint. The manipulation of the argument fields leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-7688. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
Intelligence View
SOCIAL SHARE CARD GENERATOR