Vulnerabilities (CVE)

Filtered by vendor Basic B2b Script Project Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20644 1 Basic B2b Script Project 1 Basic B2b Script 2024-02-28 6.8 MEDIUM 8.8 HIGH
PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.
CVE-2018-20645 1 Basic B2b Script Project 1 Basic B2b Script 2024-02-28 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field.
CVE-2018-20646 1 Basic B2b Script Project 1 Basic B2b Script 2024-02-28 4.0 MEDIUM 6.5 MEDIUM
PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory.
CVE-2017-17600 1 Basic B2b Script Project 1 Basic B2b Script 2024-02-28 7.5 HIGH 9.8 CRITICAL
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.