CVE-2024-9326
- EPSS 20.11%
- Veröffentlicht 29.09.2024 08:15:02
- Zuletzt bearbeitet 02.10.2024 13:33:16
A vulnerability classified as critical was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /shopping/admin/index.php of the component Admin Panel. The manipulation of the argument username leads to ...
CVE-2024-39090
- EPSS 3.08%
- Veröffentlicht 18.07.2024 20:15:04
- Zuletzt bearbeitet 05.04.2025 00:12:27
The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript ...
CVE-2023-38890
- EPSS 3.21%
- Veröffentlicht 18.08.2023 19:15:12
- Zuletzt bearbeitet 08.12.2025 17:16:06
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-...
CVE-2023-37772
- EPSS 0.27%
- Veröffentlicht 01.08.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 08:12:15
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
CVE-2023-3605
- EPSS 0.05%
- Veröffentlicht 10.07.2023 20:15:15
- Zuletzt bearbeitet 21.11.2024 08:17:39
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of exc...
CVE-2021-46110
- EPSS 0.26%
- Veröffentlicht 18.02.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:33:39
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
CVE-2021-37807
- EPSS 0.25%
- Veröffentlicht 27.10.2021 17:15:10
- Zuletzt bearbeitet 21.11.2024 06:15:55
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.