RSS   Vulnerabilities for 'E-commerce website'   RSS

2022-05-03
 
CVE-2022-27330

CWE-79
 

 
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.

 
2021-07-22
 
CVE-2021-25205

CWE-89
 

 
SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .

 


Copyright 2024, cxsecurity.com

 

Back to Top