PuneethReddyHC Vulnerabilities and Affected Products
Vulnerabilities associated with online-shopping-system-advanced.
Products
Clear product- Event Management2 vulnerabilities
- event_management2 vulnerabilities
- online-shopping-system-advanced2 vulnerabilities
- online_shopping_system_advanced2 vulnerabilities
- Online Shopping System Advanced1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-58316HIGH | Online Shopping System Advanced 1.0 SQL Injection via Payment Success ParameterOnline Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter. CWE-89Dec 12, 2025 | CVSS8.7v4.0 | EPSS0.552% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
PuneethReddyHC online-shopping-system-advanced addsuppliers.php cross site scriptingA vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231807. CWE-79Jun 18, 2023 | CVSS2.4v3.1 | EPSS0.588% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |