Known Vulnerabilities for products from Merchandise Online Store Project
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Merchandise Online Store Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-42238 json | A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboa... | 8.8 - HIGH | 2022-10-11 | 2023-08-08 |
| CVE-2022-42237 json | A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account. | 9.8 - CRITICAL | 2022-10-17 | 2022-10-19 |
| CVE-2022-42236 json | A Stored XSS issue in Merchandise Online Store v.1.0 allows to injection of Arbitrary JavaScript in edit account form. | 5.4 - MEDIUM | 2022-10-11 | 2022-10-11 |
| CVE-2022-30454 json | Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product. | 9.8 - CRITICAL | 2022-05-24 | 2022-05-28 |
| CVE-2022-30423 json | Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload poi... | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30402 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&... | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30401 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30400 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30399 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30398 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30396 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30395 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart. | 9.8 - CRITICAL | 2022-05-13 | 2022-05-23 |
| CVE-2022-30393 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=. | 7.2 - HIGH | 2022-05-13 | 2022-05-23 |
| CVE-2022-30392 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category. | 9.8 - CRITICAL | 2022-05-13 | 2022-05-23 |
| CVE-2022-30391 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category. | 9.8 - CRITICAL | 2022-05-13 | 2022-05-23 |
| CVE-2022-30387 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order. | 9.8 - CRITICAL | 2022-05-13 | 2022-05-23 |
| CVE-2022-30386 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured. | 9.8 - CRITICAL | 2022-05-13 | 2022-05-23 |
| CVE-2022-30385 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order. | 9.8 - CRITICAL | 2022-05-13 | 2022-05-23 |
| CVE-2022-30384 json | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory. | 9.8 - CRITICAL | 2022-05-13 | 2022-05-23 |
| CVE-2022-30381 json | Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img. | 6.5 - MEDIUM | 2022-05-13 | 2022-05-23 |