Critical severity9.8NVD Advisory· Published Jan 23, 2022· Updated Jun 17, 2026
CVE-2021-46024
CVE-2021-46024
Description
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
Affected products
3cpe:2.3:a:projectworlds:online-shopping-webvsite-in-php:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:projectworlds:online-shopping-webvsite-in-php:1.0:*:*:*:*:*:*:*
- (no CPE)range: = 1.0
- Projectworlds/online-shopping-webvsite-in-phpdescription
Patches
Vulnerability mechanics
References
1- github.com/projectworldsofficial/online-shopping-webvsite-in-php/issues/3nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.