Code-Projects E-Commerce Website是Code-Projects开源的一个电商网站。 Code-Projects E-Commerce Website 1.0版本存在代码注入漏洞,该漏洞源于对文件/pages/supplier_add.php中参数supp_name和supp_address的错误操作,可能导致跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | E-Commerce Website | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12301 | 7.3 HIGH | code-projects Simple Food Ordering System editproduct.php unrestricted upload |
| CVE-2025-12306 | 7.3 HIGH | code-projects Nero Social Networking Site acceptoffres.php sql injection |
| CVE-2025-12307 | 7.3 HIGH | code-projects Nero Social Networking Site addfriend.php sql injection |
| CVE-2025-12308 | 7.3 HIGH | code-projects Nero Social Networking Site deletemessage.php sql injection |
| CVE-2025-12309 | 7.3 HIGH | code-projects Nero Social Networking Site friendprofile.php sql injection |
| CVE-2025-12316 | 7.3 HIGH | code-projects Courier Management System edit-courier.php sql injection |
| CVE-2025-12243 | 6.3 MEDIUM | code-projects Client Details System GET Parameter welcome.php sql injection |
| CVE-2025-12263 | 6.3 MEDIUM | code-projects Online Event Judging System edit_judge.php sql injection |
| CVE-2025-12262 | 6.3 MEDIUM | code-projects Online Event Judging System edit_criteria.php sql injection |
| CVE-2025-12256 | 6.3 MEDIUM | code-projects Online Event Judging System edit_contestant.php sql injection |
| CVE-2025-12255 | 6.3 MEDIUM | code-projects Online Event Judging System add_contestant.php sql injection |
| CVE-2025-12254 | 6.3 MEDIUM | code-projects Online Event Judging System add_judge.php sql injection |
| CVE-2025-12252 | 6.3 MEDIUM | code-projects Online Event Judging System action.php sql injection |
| CVE-2025-12238 | 6.3 MEDIUM | code-projects Automated Voting System user.php sql injection |
| CVE-2025-12315 | 4.7 MEDIUM | code-projects Food Ordering System menu.php sql injection |
| CVE-2025-12314 | 4.7 MEDIUM | code-projects Food Ordering System deleteitem.php sql injection |
| CVE-2025-12334 | 4.3 MEDIUM | code-projects E-Commerce Website product_add.php cross site scripting |
| CVE-2025-12335 | 4.3 MEDIUM | code-projects E-Commerce Website supplier_update.php cross site scripting |
| CVE-2025-12302 | 4.3 MEDIUM | code-projects Simple Food Ordering System editproduct.php cross site scripting |
| CVE-2025-12300 | 4.3 MEDIUM | code-projects Simple Food Ordering System addcategory.php cross site scripting |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet