Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-30004
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..
0
Attacker Value
Unknown
CVE-2022-30003
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.
0
Attacker Value
Unknown
CVE-2022-29628
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.
0
Attacker Value
Unknown
CVE-2022-29627
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are owned by other sellers.
0