Description
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
In SourceCodester Online Eyewear Shop 1.0 wurde eine problematische Schwachstelle ausgemacht. Das betrifft eine unbekannte Funktionalität der Datei /oews/classes/Master.php?f=save_product. Mittels Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
| 2025-04-16: | Advisory disclosed |
| 2025-04-16: | VulDB entry created |
| 2025-04-16: | VulDB entry last update |
Credits
vulnofound (VulDB User)
vulnofound (VulDB User)
References
github.com/vulnofound/cve/blob/main/xss.md
vuldb.com/?id.304981 (VDB-304981 | SourceCodester Online Eyewear Shop Master.php cross site scripting)
vuldb.com/?ctiid.304981 (VDB-304981 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.553520 (Submit #553520 | sourcecodester Online optical shop website v1.0 Stored XSS)
github.com/vulnofound/cve/blob/main/xss.md
www.sourcecodester.com/