Vendorsoretnom23online_medicine_ordering_systemall versions
Vulnerabilities

oretnom23 Online Medicine Ordering System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-25217
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.
Published 2024-02-14 · Modified
9.8EPSS 0.007
CVE-2025-3140
SourceCodester Online Medicine Ordering System view_category.php sql injection
Published 2025-04-03 · Analyzed
9.8EPSS 0.006
CVE-2025-3141
SourceCodester Online Medicine Ordering System manage_category.php sql injection
Published 2025-04-03 · Analyzed
9.8EPSS 0.006
CVE-2024-46293
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.
Published 2024-09-30 · Analyzed
9.8EPSS 0.004
CVE-2022-3714
SourceCodester Online Medicine Ordering System sql injection
Published 2022-10-27 · Modified
9.8EPSS 0.004
CVE-2024-32167
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.
Published 2024-06-10 · Modified
9.1EPSS 0.007
CVE-2022-3716
SourceCodester Online Medicine Ordering System cross site scripting
Published 2022-10-27 · Modified
5.4EPSS 0.004