📦 Online Eyewear Shop

by Oretnom23

🔍 What is Online Eyewear Shop?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2846

HIGH CVSS 7.3 Mar 27, 2025

This critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to execute arbitrary SQL commands through the registration function. Remote attackers can potential...

CVE-2024-5894

HIGH CVSS 7.3 Jun 12, 2024

This critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in manage_product.php. Attackers ca...

CVE-2025-3298

MEDIUM CVSS 4.3 Apr 5, 2025

This vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to bypass access controls through manipulation of the email parameter in the registration handler. Attackers can exploit t...

CVE-2025-3018

MEDIUM CVSS 6.3 Mar 31, 2025

This critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to manipulate database queries through the /classes/Users.php?f=delete endpoint. Remote attackers c...

CVE-2025-2651

MEDIUM CVSS 5.3 Mar 23, 2025

This vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to view directory listings in the /oews/admin/ path and subdirectories remotely. This exposes sensitive file and directory...

CVE-2024-9974

MEDIUM CVSS 6.3 Oct 15, 2024

This vulnerability allows remote attackers to execute arbitrary SQL commands via the product_id parameter in the add_to_card functionality of SourceCodester Online Eyewear Shop 1.0. Attackers can pote...

CVE-2024-9808

MEDIUM CVSS 6.3 Oct 10, 2024

This is a critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /admin/?page=produ...

CVE-2024-9082

MEDIUM CVSS 6.3 Sep 22, 2024

This vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to bypass authorization controls during user creation. By manipulating the 'Type' parameter with input '1', attackers can ...