CVE-2021-41649
CRITICAL EXPLOITED NUCLEIOnline-shopping-system-advanced - SQL Injection
Title source: ruleDescription
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
Exploits (1)
Nuclei Templates (1)
PuneethReddyHC Online Shopping System homeaction.php SQL Injection
CRITICALby daffainfo
References (4)
Scores
CVSS v3
9.8
EPSS
0.9202
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-01-22
CWE
CWE-89
Status
published
Products (1)
online-shopping-system-advanced_project/online-shopping-system-advanced
Published
Oct 01, 2021
Tracked Since
Feb 18, 2026