Product
ReadyEcommerce versions before 4.5.2 are vulnerable to unauthenticated time-based blind SQL injection in the product listing API, allowing attackers to exfiltrate database contents and potentially gain system-level access.