VYPR
Critical severity9.8NVD Advisory· Published Aug 17, 2021· Updated Jun 17, 2026

CVE-2020-18164

CVE-2020-18164

Description

SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

Affected products

3
  • Tp Shop/Tpshop2 versions
    cpe:2.3:a:tp-shop:tp-shop:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tp-shop:tp-shop:*:*:*:*:*:*:*:*range: >=2.0.5,<=3.0.0
    • (no CPE)range: 2.x-3.x
  • tp-shop/tp-shopdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.