Show filters
545 Total Results
Displaying 81-90 of 545
Sort by:
Attacker Value
Unknown

CVE-2024-45119

Disclosure Date: October 10, 2024 (last updated December 18, 2024)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2024-45118

Disclosure Date: October 10, 2024 (last updated October 12, 2024)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have high impact on integrity. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2024-45117

Disclosure Date: October 10, 2024 (last updated October 12, 2024)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An admin attacker could exploit this vulnerability to read files from the system outside of the intended directories via PHP filter chain and also can have a low-availability impact on the service. Exploitation of this issue does not require user interaction and scope is changed.
Attacker Value
Unknown

CVE-2024-45116

Disclosure Date: October 10, 2024 (last updated October 12, 2024)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. If an admin attacker can trick a user into clicking a specially crafted link or submitting a form, malicious scripts may be executed within the context of the victim's browser and have high impact on confidentiality and integrity. Exploitation of this issue requires user interaction.
Attacker Value
Unknown

CVE-2024-45115

Disclosure Date: October 10, 2024 (last updated October 12, 2024)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within the application. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2024-45278

Disclosure Date: October 08, 2024 (last updated November 15, 2024)
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2024-45366

Disclosure Date: September 18, 2024 (last updated September 18, 2024)
Welcart e-Commerce prior to 2.11.2 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.
0
Attacker Value
Unknown

CVE-2024-42404

Disclosure Date: September 18, 2024 (last updated September 18, 2024)
SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database.
0
Attacker Value
Unknown

CVE-2024-46938

Disclosure Date: September 15, 2024 (last updated September 21, 2024)
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Attacker Value
Unknown

CVE-2024-8217

Disclosure Date: August 27, 2024 (last updated August 30, 2024)
A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.