Merchandise Online Store Project
Merchandise Online Store Project Merchandise Online Store: vulnerabilidades y CVE
Merchandise Online Store Project Merchandise Online Store tiene 20 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses0
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-42237 | Crítica (9.8) | 0.91% | — | 17 oct 2022 | A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account. |
| CVE-2022-42238 | Alta (8.8) | 0.88% | — | 11 oct 2022 | A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard. |
| CVE-2022-42236 | Media (5.4) | 0.43% | — | 11 oct 2022 | A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form. |
| CVE-2022-30423 | Crítica (9.8) | 1.8% | — | 2 jun 2022 | Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information. |
| CVE-2022-30454 | Crítica (9.8) | 1.1% | — | 24 may 2022 | Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product. |
| CVE-2022-30402 | Alta (7.2) | 0.97% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=. |
| CVE-2022-30401 | Alta (7.2) | 0.97% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=. |
| CVE-2022-30400 | Alta (7.2) | 0.97% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=. |
| CVE-2022-30399 | Alta (7.2) | 0.97% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=. |
| CVE-2022-30398 | Alta (7.2) | 0.97% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=. |
| CVE-2022-30396 | Alta (7.2) | 0.97% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=. |
| CVE-2022-30395 | Crítica (9.8) | 1.1% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart. |
| CVE-2022-30393 | Alta (7.2) | 0.97% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=. |
| CVE-2022-30392 | Crítica (9.8) | 1.1% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category. |
| CVE-2022-30391 | Crítica (9.8) | 1.1% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category. |
| CVE-2022-30387 | Crítica (9.8) | 0.94% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order. |
| CVE-2022-30386 | Crítica (9.8) | 1.1% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured. |
| CVE-2022-30385 | Crítica (9.8) | 1.1% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order. |
| CVE-2022-30384 | Crítica (9.8) | 1.1% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory. |
| CVE-2022-30381 | Media (6.5) | 0.94% | — | 13 may 2022 | Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img. |