VYPR

Online Shopping Alphaware

by Online Shopping Alphaware Project

CVEs (2)

  • CVE-2020-24208CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.

  • CVE-2020-25362HigJun 2, 2021
    risk 0.49cvss 7.5epss 0.02

    The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.