First published: Wed Dec 22 2021(Updated: )
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Online Shopping System In Php | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43158 is a CSRF vulnerability in cart_remove.php in ProjectWorlds Online Shopping System PHP 1.0.
CVE-2021-43158 allows a remote attacker to remove any product in the customer's cart.
CVE-2021-43158 is considered to have a severity level of medium (4.3).
You can find more information about CVE-2021-43158 on the GitHub repository issue page (https://github.com/projectworldsofficial/online-shopping-webvsite-in-php/issues/2) and the ProjectWorlds website (https://projectworlds.in/free-projects/php-projects/free-download-online-shopping-system/).
To fix CVE-2021-43158, it is recommended to apply the latest security patch or update provided by ProjectWorlds.