Vulnerabilities (CVE)

Filtered by vendor Online Shopping Alphaware Project Subscribe
Filtered by product Online Shopping Alphaware
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25362 1 Online Shopping Alphaware Project 1 Online Shopping Alphaware 2023-12-10 5.0 MEDIUM 7.5 HIGH
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
CVE-2020-24208 1 Online Shopping Alphaware Project 1 Online Shopping Alphaware 2023-12-10 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.