Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter.
Metrics
Affected Vendors & Products
References
History
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Puneethreddyhc
Puneethreddyhc online Shopping System Advanced |
|
| Vendors & Products |
Puneethreddyhc
Puneethreddyhc online Shopping System Advanced |
Fri, 12 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter. | |
| Title | Online Shopping System Advanced 1.0 SQL Injection via Payment Success Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-12T20:14:23.741Z
Updated: 2025-12-12T20:49:46.349Z
Reserved: 2025-12-12T20:13:07.794Z
Link: CVE-2024-58316
Updated: 2025-12-12T20:49:42.859Z
Status : Received
Published: 2025-12-12T21:15:51.430
Modified: 2025-12-12T21:15:51.430
Link: CVE-2024-58316
No data.
ReportizFlow