Description
A vulnerability was detected in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/admin_feature.php of the component Add Product Page. The manipulation of the argument product_name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-04-05: | Advisory disclosed |
| 2026-04-05: | VulDB entry created |
| 2026-04-05: | VulDB entry last update |
Credits
Jacky_159 (VulDB User)
References
vuldb.com/vuln/355435 (VDB-355435 | code-projects Online Shoe Store Add Product admin_feature.php cross site scripting)
vuldb.com/vuln/355435/cti (VDB-355435 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/786171 (Submit #786171 | code-projects Online Shoe Store V1.0 cross site scripting)
github.com/Jacky159/Pub_0323/issues/1
code-projects.org/