VendorsOnline-shopping-system-advanced Projectonline-shopping-system-advancedall versions
Vulnerabilities

Online-shopping-system-advanced Project Online-shopping-system-advanced

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-41649
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
Published 2021-10-01 · Modified
9.8EPSS 0.518
CVE-2022-42109
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
Published 2022-11-29 · Modified
9.8EPSS 0.011
CVE-2021-41648
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
Published 2021-10-01 · Modified
7.5EPSS 0.102
CVE-2023-3311
PuneethReddyHC online-shopping-system-advanced addsuppliers.php cross site scripting
Published 2023-06-18 · Modified
5.4EPSS 0.006