Show filters
87 Total Results
Displaying 41-50 of 87
Sort by:
Attacker Value
Unknown
CVE-2020-26223
Disclosure Date: November 13, 2020 (last updated February 22, 2025)
Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.
0
Attacker Value
Unknown
CVE-2020-25093
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
0
Attacker Value
Unknown
CVE-2020-25086
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
0
Attacker Value
Unknown
CVE-2020-25087
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
0
Attacker Value
Unknown
CVE-2020-25091
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
0
Attacker Value
Unknown
CVE-2020-25089
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
0
Attacker Value
Unknown
CVE-2020-25090
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
0
Attacker Value
Unknown
CVE-2020-25092
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.
0
Attacker Value
Unknown
CVE-2020-25088
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
0
Attacker Value
Unknown
CVE-2019-17605
Disclosure Date: November 07, 2019 (last updated November 27, 2024)
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.
0