VYPR

Online Shopping System Advanced

by Online Shopping System Advanced Project

CVEs (5)

  • CVE-2021-41649CriOct 1, 2021
    risk 0.68cvss 9.8epss 0.52

    An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

  • CVE-2022-42109CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.

  • CVE-2021-41648HigOct 1, 2021
    risk 0.50cvss 7.5epss 0.10

    An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.

  • CVE-2023-3337HigJun 20, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in PuneethReddyHC Online Shopping System Advanced 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/reg.php of the component Admin Registration. The manipulation leads to improper…

  • CVE-2023-3311LowJun 18, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate…