CVE-2021-43158: CSRF
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cartremove.php allows a remote attacker to remove any product in the customer's cart.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43158?
CVE-2021-43158 is a CSRF vulnerability in cart_remove.php in ProjectWorlds Online Shopping System PHP 1.0.
How does CVE-2021-43158 affect ProjectWorlds Online Shopping System PHP?
CVE-2021-43158 allows a remote attacker to remove any product in the customer's cart.
What is the severity of CVE-2021-43158?
CVE-2021-43158 is considered to have a severity level of medium (4.3).
Where can I find more information about CVE-2021-43158?
You can find more information about CVE-2021-43158 on the GitHub repository issue page (https://github.com/projectworldsofficial/online-shopping-webvsite-in-php/issues/2) and the ProjectWorlds website (https://projectworlds.in/free-projects/php-projects/free-download-online-shopping-system/).
How can I fix CVE-2021-43158 in ProjectWorlds Online Shopping System PHP?
To fix CVE-2021-43158, it is recommended to apply the latest security patch or update provided by ProjectWorlds.