Showing 1 vulnerability on this page for online-shopping-system-advanced

Signals CISA KEV Ransomware Nuclei
online-shopping-system-advanced_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

online-shopping-system-advanced_project online-shopping-system-advanced Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CWE-89Oct 1, 20211 related artifact
CVSS9.8v3.1EPSS51.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX