Vulnerabilities > Iorder Project

DATE CVE VULNERABILITY TITLE RISK
2021-12-20 CVE-2021-43440 Cross-site Scripting vulnerability in Iorder Project Iorder 1.0
Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code via signup form in the Name and Phone number field.
network
low complexity
iorder-project CWE-79
6.1
2021-12-20 CVE-2021-43441 Cross-site Scripting vulnerability in Iorder Project Iorder 1.0
An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup form
network
low complexity
iorder-project CWE-79
5.3