VendorsEcommerce-Website Projectecommerce-website1.1.0
Vulnerabilities

Ecommerce-Website Project Ecommerce-Website 1.1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-27346
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-04-08 · Modified
8.8EPSS 0.027
CVE-2022-27435
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
Published 2022-04-04 · Modified
8.8EPSS 0.017
CVE-2022-27436
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
Published 2022-04-04 · Modified
4.8EPSS 0.010