Showing 2 vulnerabilities on this page for online-shopping-system-advanced

Signals CISA KEV Ransomware Nuclei
PuneethReddyHC vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Online Shopping System Advanced 1.0 SQL Injection via Payment Success Parameter

Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter.

CWE-89Dec 12, 2025
CVSS8.7v4.0EPSS0.552%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

PuneethReddyHC online-shopping-system-advanced addsuppliers.php cross site scripting

A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231807.

CWE-79Jun 18, 2023
CVSS2.4v3.1EPSS0.588%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX