Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or manipulate database information by sending crafted payloads to the collections page.
History

Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Elements
Elements xhibiter Nft Marketplace
Vendors & Products Elements
Elements xhibiter Nft Marketplace

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
Description Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or manipulate database information by sending crafted payloads to the collections page.
Title Xhibiter NFT Marketplace 1.10.2 SQL Injection via Collections Endpoint
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-11T21:34:52.311Z

Reserved: 2025-12-10T23:46:14.009Z

Link: CVE-2024-58290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-11T22:15:49.763

Modified: 2025-12-12T15:17:31.973

Link: CVE-2024-58290

cve-icon Redhat

No data.