Merchandise Online Store
by Merchandise Online Store Project
CVEs (20)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42237 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2022 | A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account. | ||
| CVE-2022-30423 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information. | ||
| CVE-2022-30454 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2022 | Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product. | ||
| CVE-2022-30395 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart. | ||
| CVE-2022-30392 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category. | ||
| CVE-2022-30391 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category. | ||
| CVE-2022-30387 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order. | ||
| CVE-2022-30386 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured. | ||
| CVE-2022-30385 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order. | ||
| CVE-2022-30384 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory. | ||
| CVE-2022-42238 | Hig | 0.57 | 8.8 | 0.01 | Oct 11, 2022 | A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard. | ||
| CVE-2022-30402 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=. | ||
| CVE-2022-30401 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=. | ||
| CVE-2022-30400 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=. | ||
| CVE-2022-30399 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=. | ||
| CVE-2022-30398 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=. | ||
| CVE-2022-30396 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=. | ||
| CVE-2022-30393 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=. | ||
| CVE-2022-30381 | Med | 0.42 | 6.5 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img. | ||
| CVE-2022-42236 | Med | 0.35 | 5.4 | 0.00 | Oct 11, 2022 | A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form. |
- risk 0.64cvss 9.8epss 0.01
A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.
- risk 0.64cvss 9.8epss 0.02
Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.
- risk 0.57cvss 8.8epss 0.01
A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=.
- risk 0.42cvss 6.5epss 0.01
Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.
- risk 0.35cvss 5.4epss 0.00
A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form.