Mahendra Purbia

3 exploits Active since Dec 2020
CVE-2020-36115 EXPLOITDB MEDIUM text WRITEUP
Egavilanmedia Phpcrud - XSS
Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.
CVSS 5.4
CVE-2020-28838 EXPLOITDB LOW text WORKING POC
Opencart - CSRF
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.
CVSS 3.5
EIP-2026-110274 EXPLOITDB text WRITEUP
OpenCart 3.0.36 - ATO via Cross Site Request Forgery