Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Online Shopping Alphaware Project Subscribe
Filtered by product Online Shopping Alphaware
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25362 1 Online Shopping Alphaware Project 1 Online Shopping Alphaware 2021-06-09 5.0 MEDIUM 7.5 HIGH
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
CVE-2020-24208 1 Online Shopping Alphaware Project 1 Online Shopping Alphaware 2020-08-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.