Vulnerabilities > Merchandise Online Store Project > Merchandise Online Store > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-11 | CVE-2022-42236 | Cross-site Scripting vulnerability in Merchandise Online Store Project Merchandise Online Store 1.0 A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form. | 5.4 |
2022-05-13 | CVE-2022-30381 | Unspecified vulnerability in Merchandise Online Store Project Merchandise Online Store 1.0 Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img. | 6.5 |