在 code-projects 的在线购物系统 1.0 中发现一个漏洞。该漏洞影响 Newsletter Subscription(新闻订阅)组件中文件 /offersmail.php 的某项未知功能。对参数 email 进行操控会引发跨站脚本攻击(XSS)。该攻击可由远程发起,且利用代码已经公开,可能存在被利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Online Shopping System | 1.0 |
cpe:2.3:a:code-projects:online_shopping_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82701 | 7.3 HIGH | code-projects Online Shopping System Search Functionality action.php sql injection |
| CVE-2026-82624 | 5.3 MEDIUM | code-projects Simple Inventory System Database Backup File inventorymanagement.sql informa |
| CVE-2026-82625 | 4.3 MEDIUM | code-projects Simple Inventory System User Registration register.php cross site scripting |
| CVE-2026-82622 | 3.5 LOW | code-projects Employee Leave Managing System Employee Profile Update editaction.php cross |
No comments yet