Vulnerabilities > Exrick

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-24112 SQL Injection vulnerability in Exrick Xmall 1.1
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
network
low complexity
exrick CWE-89
critical
9.8
2022-04-07 CVE-2021-43432 Cross-site Scripting vulnerability in Exrick Xmall 1.1
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.
network
low complexity
exrick CWE-79
6.1