Vulnerabilities (CVE)

Filtered by vendor Projectworlds Subscribe
Filtered by product Online Shopping System In Php
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43157 1 Projectworlds 1 Online Shopping System In Php 2024-02-04 7.5 HIGH 9.8 CRITICAL
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
CVE-2021-43158 1 Projectworlds 1 Online Shopping System In Php 2024-02-04 4.3 MEDIUM 4.3 MEDIUM
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.