Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2022-26954
Disclosure Date: October 20, 2022 (last updated February 24, 2025)
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class.
0
Attacker Value
Unknown
CVE-2022-33077
Disclosure Date: October 19, 2022 (last updated February 24, 2025)
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
0
Attacker Value
Unknown
CVE-2022-27461
Disclosure Date: May 04, 2022 (last updated February 23, 2025)
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
0
Attacker Value
Unknown
CVE-2022-28451
Disclosure Date: May 02, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
0
Attacker Value
Unknown
CVE-2022-28450
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
0
Attacker Value
Unknown
CVE-2022-28449
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
0
Attacker Value
Unknown
CVE-2022-28448
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
0
Attacker Value
Unknown
CVE-2021-26916
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.
0
Attacker Value
Unknown
CVE-2020-29475
Disclosure Date: December 29, 2020 (last updated February 22, 2025)
nopCommerce Store 4.30 is affected by cross-site scripting (XSS) in the Schedule tasks name field. This vulnerability can allow an attacker to inject the XSS payload in Schedule tasks and each time any user will go to that page of the website, the XSS triggers and attacker can able to steal the cookie according to the crafted payload.
0
Attacker Value
Unknown
CVE-2019-19685
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
0