Vulnerabilities > PHP Multivendor Ecommerce Project > PHP Multivendor Ecommerce > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-12-28 | CVE-2017-17960 | Cross-Site Request Forgery (CSRF) vulnerability in PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. | 8.8 |
2017-12-28 | CVE-2017-17952 | Improper Input Validation vulnerability in PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. | 8.6 |