Known Vulnerabilities for Merchandise Online Store by Merchandise Online Store Project
Listed below are 10 of the newest known vulnerabilities associated with "Merchandise Online Store" by "Merchandise Online Store Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-42238 json | A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboa... | 8.8 - HIGH | 2022-10-11 | 2023-08-08 |
| CVE-2022-42237 json | A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account. | 9.8 - CRITICAL | 2022-10-17 | 2022-10-19 |
| CVE-2022-42236 json | A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form. | 5.4 - MEDIUM | 2022-10-11 | 2022-10-11 |
| CVE-2022-30454 json | Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product. | 9.8 - CRITICAL | 2022-05-24 | 2022-05-28 |
| CVE-2022-30423 json | Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload poi... | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30402 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&... | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30401 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30400 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30399 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30398 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |