Exrick
Exrick Xmall: vulnerabilidades y CVE
Exrick Xmall tiene 7 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses3
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90571 | Media (5.3) | 0.47% | — | 13 sept 2026 | A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order… |
| CVE-2023-36331 | Alta (8.2) | 0.23% | — | 12 ene 2026 | Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId. |
| CVE-2025-65540 | Media (6.1) | 0.18% | — | 29 nov 2025 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper… |
| CVE-2025-45612 | Crítica (9.8) | 0.54% | — | 5 may 2025 | Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. |
| CVE-2025-28399 | Crítica (9.8) | 0.61% | — | 15 abr 2025 | An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. |
| CVE-2024-24112 | Crítica (9.8) | 3.3% | — | 6 feb 2024 | xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. |
| CVE-2021-43432 | Media (6.1) | 0.84% | — | 7 abr 2022 | A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.