Show filters
378 Total Results
Displaying 171-180 of 378
Sort by:
Attacker Value
Unknown
CVE-2022-33077
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
0
Attacker Value
Unknown
CVE-2022-2555
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2022-35213
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.
0
Attacker Value
Unknown
CVE-2022-35212
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
osCommerce2 before v2.3.4.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the function tep_db_error().
0
Attacker Value
Unknown
CVE-2022-2372
Disclosure Date: August 08, 2022 (last updated February 24, 2025)
The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-2371
Disclosure Date: August 08, 2022 (last updated February 24, 2025)
The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.
0
Attacker Value
Unknown
CVE-2022-2682
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce System. Affected by this issue is some unknown functionality of the file stockin.php. The manipulation of the argument id with the input '"><script>alert(/xss/)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-205670 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-2678
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown code of the file admin_feature.php of the component Background Management Page. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205666 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-2369
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
0
Attacker Value
Unknown
CVE-2022-2370
Disclosure Date: August 01, 2022 (last updated February 24, 2025)
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
0