Known Vulnerabilities for products from Online Store System Project
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Online Store System Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-8292 json | Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowi... | 5.3 - MEDIUM | 2019-10-01 | 2022-10-14 |
| CVE-2019-8291 json | Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path ... | 7.5 - HIGH | 2019-10-01 | 2019-10-07 |
| CVE-2019-8290 json | Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting... | 6.1 - MEDIUM | 2019-10-01 | 2019-10-04 |
| CVE-2019-8289 json | Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable | 5.4 - MEDIUM | 2019-10-01 | 2019-10-04 |
| CVE-2019-8288 json | Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized. | 5.4 - MEDIUM | 2019-10-01 | 2019-10-04 |
Known software with vulnerabilities from Online Store System Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Online Store System Project | Online Store System | 1.0 |