A vulnerability classified as critical has been found in opencartextensions Extension TMD Vendor System 3.0. The impacted element is an unknown function. The manipulation of the argument product_id leads to sql injection.
This vulnerability is documented as CVE-2021-47928. The attack can be initiated remotely. Additionally, an exploit exists.