Aggregates CVE and security vulnerability intelligence across all online_store_system_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk cross-site scripting and vendor risk path handling and related problems; some flaws may lead to vendor impact session compromise and vendor impact file overwrite.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2019-8292 | Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion. | [email protected] | 5.3 | 0.35% | 2019-10-01 | 2024-11-21 |
| CVE-2019-8291 | Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal. | [email protected] | 7.5 | 0.29% | 2019-10-01 | 2024-11-21 |
| CVE-2019-8290 | Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected. | [email protected] | 6.1 | 0.30% | 2019-10-01 | 2024-11-21 |
| CVE-2019-8289 | Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable | [email protected] | 5.4 | 0.26% | 2019-10-01 | 2024-11-21 |
| CVE-2019-8288 | Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized. | [email protected] | 5.4 | 0.26% | 2019-10-01 | 2024-11-21 |