在 code-projects 的 Online Shopping System(在线购物系统)1.0 中发现了一个漏洞。该漏洞位于 Search Functionality(搜索功能)组件中 /action.php 文件的某个未知功能模块中。对 参数的操纵会导致 SQL 注入。该攻击可远程发起。此漏洞的利用方式已公开披露,并可能被利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Online Shopping System | 1.0 |
cpe:2.3:a:code-projects:online_shopping_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82624 | 5.3 MEDIUM | code-projects Simple Inventory System Database Backup File inventorymanagement.sql informa |
| CVE-2026-82700 | 4.3 MEDIUM | code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scr |
| CVE-2026-82625 | 4.3 MEDIUM | code-projects Simple Inventory System User Registration register.php cross site scripting |
| CVE-2026-82622 | 3.5 LOW | code-projects Employee Leave Managing System Employee Profile Update editaction.php cross |
No comments yet