Vulnerability Description
Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by manipulating the user ID parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Puneethreddyhc | Online Shopping System Advanced | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/PuneethReddyHC/online-shopping-system-advancedProduct
- https://www.exploit-db.com/exploits/51811ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/online-shopping-system-advanced-sql-injectiThird Party Advisory
FAQ
What is CVE-2024-58316?
CVE-2024-58316 is a vulnerability with a CVSS score of 7.5 (HIGH). Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attack...
How severe is CVE-2024-58316?
CVE-2024-58316 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-58316?
Check the references section above for vendor advisories and patch information. Affected products include: Puneethreddyhc Online Shopping System Advanced.