CVE-2021-46024

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
23/01/2022
Last modified:
27/01/2022

Description

Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:projectworlds:online-shopping-webvsite-in-php:1.0:*:*:*:*:*:*:*