VYPR

Online Market Place Site

by Sourcecodester

CVEs (2)

  • CVE-2022-30004CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

  • CVE-2022-30003MedSep 26, 2022
    risk 0.35cvss 5.4epss 0.01

    Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.