CVE-2021-47909Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database management system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-01); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-01: 1Mentions · 2026-02-05: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-05: 102-0102-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2021-47909 Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or… https://www.cve.org/CVERecord?id=CVE-2021-47909

    Post summary

    The text discloses that CVE-2021-47909 affects Mult‑E‑Cart Ultimate 2.4 with several SQL injection points across key modules, but provides no evidence of exploitation, patches, or PoCs.

    00010258
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2021-47909 (CVSS:8.6, HIGH) is Awaiting Analysis. Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modul..https://nvd.nist.gov/vuln/detail/CVE-2021-47909 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces the CVE-2021-47909 with high severity and technical details about its SQL injection flaws, but offers no PoC, exploit, or patch information.

    0000055
    171 followersView on X

Explore more