Product GitHub Repositoryproduct
https://github.com/PuneethReddyHC/online-shopping-system-advanced CVE-2024-58316
HIGH
Online Shopping System Advanced 1.0 SQL Injection via Payment Success Parameter
Record summary
CVE-2024-58316 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
online-shopping-system-advancedBrowse PuneethReddyHC / online-shopping-system-advancedDefault status: unaffected | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBOnline Shopping System Advanced - Sql InjectionExploitDB exploitby Furkan GedikNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58316 ExploitDB-51811exploit
https://www.exploit-db.com/exploits/51811 VulnCheck Advisory: Online Shopping System Advanced 1.0 SQL Injection via Payment Success ParameterThird-party advisory
https://www.vulncheck.com/advisories/online-shopping-system-advanced-sql-injection-via-payment-success-parameter