VYPR
Vendor

Tp Shop

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2020-18164CriAug 17, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

  • CVE-2018-9919CriMay 2, 2018
    risk 0.64cvss 9.8epss 0.05

    A web-accessible backdoor, with resultant SSRF, exists in Tp-shop 2.0.5 through 2.0.8, which allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution, because /vendor/phpdocumentor/reflection-docblock/tests/phpDo…

  • CVE-2017-16614CriMar 30, 2018
    risk 0.64cvss 9.8epss 0.03

    SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter.