📦 Merchandise Online Store

by Merchandise Online Store Project

🔍 What is Merchandise Online Store?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-30454

CRITICAL CVSS 9.8 May 24, 2022

Merchandise Online Store 1.0 contains a SQL injection vulnerability in the delete_product function that allows attackers to execute arbitrary SQL commands. This affects all deployments of version 1.0,...

CVE-2022-30384

CRITICAL CVSS 9.8 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_inventory function that allows attackers to execute arbitrary SQL commands. This affects all installations of this sp...

CVE-2022-30386

CRITICAL CVSS 9.8 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_featured function that allows attackers to execute arbitrary SQL commands. This affects all deployments of this speci...

CVE-2022-30391

CRITICAL CVSS 9.8 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_category function that allows attackers to execute arbitrary SQL commands. This affects all installations of the vuln...

CVE-2022-30395

CRITICAL CVSS 9.8 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the delete_cart function that allows attackers to execute arbitrary SQL commands. This affects all users running the vulnerable ...

CVE-2022-30393

HIGH CVSS 7.2 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the product management admin interface. Attackers can inject malicious SQL queries through the 'id' parameter to manipulate data...

CVE-2022-30398

HIGH CVSS 7.2 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the order viewing functionality of the admin panel. Attackers can exploit this by manipulating the 'id' parameter to execute arb...

CVE-2022-30400

HIGH CVSS 7.2 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the admin orders view page that allows attackers to execute arbitrary SQL commands via the 'id' parameter. This affects all depl...

CVE-2022-30402

HIGH CVSS 7.2 May 13, 2022

Merchandise Online Store v1.0 contains a SQL injection vulnerability in the admin panel's subcategory management page. Attackers can exploit this to execute arbitrary SQL commands, potentially accessi...