Vulnerabilities > Ecommerce Website Project

DATE CVE VULNERABILITY TITLE RISK
2022-12-05 CVE-2022-45990 Cross-site Scripting vulnerability in Ecommerce-Website Project Ecommerce-Website 1.0
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
network
low complexity
ecommerce-website-project CWE-79
6.1
2022-04-08 CVE-2022-27346 Unrestricted Upload of File with Dangerous Type vulnerability in Ecommerce-Website Project Ecommerce-Website 1.1.0
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides.
network
low complexity
ecommerce-website-project CWE-434
8.8
2022-04-08 CVE-2022-27357 Unrestricted Upload of File with Dangerous Type vulnerability in Ecommerce-Website Project Ecommerce-Website 1.0
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php.
network
low complexity
ecommerce-website-project CWE-434
critical
9.8
2022-04-04 CVE-2022-27435 Unrestricted Upload of File with Dangerous Type vulnerability in Ecommerce-Website Project Ecommerce-Website 1.1.0
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
network
low complexity
ecommerce-website-project CWE-434
8.8
2022-04-04 CVE-2022-27436 Cross-site Scripting vulnerability in Ecommerce-Website Project Ecommerce-Website 1.1.0
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
network
low complexity
ecommerce-website-project CWE-79
4.8