Filtered by vendor Online Market Place Site Project
Subscriptions
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-30003 | 1 Online Market Place Site Project | 1 Online Market Place Site | 2022-09-28 | 5.4 Medium |
Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields. | ||||
CVE-2022-30004 | 1 Online Market Place Site Project | 1 Online Market Place Site | 2022-09-28 | 9.8 Critical |
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection.. | ||||
CVE-2022-29627 | 1 Online Market Place Site Project | 1 Online Market Place Site | 2022-06-12 | 4.3 Medium |
An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers. | ||||
CVE-2022-29628 | 1 Online Market Place Site Project | 1 Online Market Place Site | 2022-06-09 | 5.4 Medium |
A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter. |
Page 1 of 1.