CVE-2022-33077
- EPSS 0.2%
- Veröffentlicht 19.10.2022 02:15:08
- Zuletzt bearbeitet 09.05.2025 15:15:53
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
CVE-2022-27461
- EPSS 0.2%
- Veröffentlicht 04.05.2022 15:15:12
- Zuletzt bearbeitet 21.11.2024 06:55:46
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
CVE-2022-28451
- EPSS 0.65%
- Veröffentlicht 02.05.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:22
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
CVE-2022-28450
- EPSS 0.15%
- Veröffentlicht 26.04.2022 21:15:45
- Zuletzt bearbeitet 21.11.2024 06:57:22
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
CVE-2022-28449
- EPSS 0.24%
- Veröffentlicht 26.04.2022 21:15:45
- Zuletzt bearbeitet 21.11.2024 06:57:22
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
CVE-2022-28448
- EPSS 0.19%
- Veröffentlicht 26.04.2022 20:15:35
- Zuletzt bearbeitet 21.11.2024 06:57:22
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
CVE-2021-26916
- EPSS 0.22%
- Veröffentlicht 08.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:02
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.
CVE-2019-19685
- EPSS 0.14%
- Veröffentlicht 09.12.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:11
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
CVE-2019-19684
- EPSS 0.39%
- Veröffentlicht 09.12.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:11
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.
CVE-2019-19683
- EPSS 0.62%
- Veröffentlicht 09.12.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:11
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.