VYPR

Complete E-Commerce Site

by Sourcecodester

CVEs (2)

  • CVE-2024-30849CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.

  • CVE-2024-2754MedMar 21, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack…