Vulnerabilities > Iorder Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-20 | CVE-2021-43440 | Cross-site Scripting vulnerability in Iorder Project Iorder 1.0 Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code via signup form in the Name and Phone number field. | 6.1 |
2021-12-20 | CVE-2021-43441 | Cross-site Scripting vulnerability in Iorder Project Iorder 1.0 An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup form | 5.3 |