
CVE-2025-3298 – SourceCodester Online Eyewear Shop Registration Master.php access control
https://notcve.org/view.php?id=CVE-2025-3298
05 Apr 2025 — A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads to improper access controls. The attack can be launched remotely. • https://vuldb.com/?id.303493 • CWE-266: Incorrect Privilege Assignment CWE-284: Improper Access Control •

CVE-2025-3297 – SourceCodester Online Eyewear Shop Master.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-3297
05 Apr 2025 — A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. • https://github.com/foreverfeifei/cve/blob/main/xss.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-3296 – SourceCodester Online Eyewear Shop Users.php sql injection
https://notcve.org/view.php?id=CVE-2025-3296
05 Apr 2025 — A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=delete_customer. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. • https://github.com/foreverfeifei/cve/blob/main/sql.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3018 – SourceCodester Online Eyewear Shop Users.php sql injection
https://notcve.org/view.php?id=CVE-2025-3018
31 Mar 2025 — A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. • https://vuldb.com/?id.302070 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-2846 – SourceCodester Online Eyewear Shop Registration Users.php registration sql injection
https://notcve.org/view.php?id=CVE-2025-2846
27 Mar 2025 — A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of the file /oews/classes/Users.php?f=registration of the component Registration. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. • https://github.com/jeajeaa/cve/blob/main/sql.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-2651 – SourceCodester Online Eyewear Shop admin exposure of information through directory listing
https://notcve.org/view.php?id=CVE-2025-2651
23 Mar 2025 — A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/happytraveller-alone/cve/blob/main/Directory%20Traversal%20Vulnerability.md • CWE-548: Exposure of Information Through Directory Listing CWE-552: Files or Directories Accessible to External Parties •

CVE-2025-0173 – SourceCodester Online Eyewear Shop view_order.php sql injection
https://notcve.org/view.php?id=CVE-2025-0173
02 Jan 2025 — A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /orders/view_order.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/listlonely/cve/blob/main/sql.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-11247 – SourceCodester Online Eyewear Shop Inventory Page Master.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-11247
15 Nov 2024 — A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Inventory Page. The manipulation of the argument brand leads to cross site scripting. The attack can be launched remotely. • https://github.com/Fl4g-Pshacker/cve/blob/main/xss.md • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2024-9974 – SourceCodester Online Eyewear Shop POST Request Master.php sql injection
https://notcve.org/view.php?id=CVE-2024-9974
15 Oct 2024 — A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=add_to_card of the component POST Request Handler. The manipulation of the argument product_id leads to sql injection. • https://gist.github.com/higordiego/2373b9e3e89f03e5f8888efd38eb4b48 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-9973 – SourceCodester Online Eyewear Shop Report Viewing Page page sql injection
https://notcve.org/view.php?id=CVE-2024-9973
15 Oct 2024 — A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports of the component Report Viewing Page. The manipulation of the argument date leads to sql injection. • https://gist.github.com/higordiego/b9699573de61b26f2290e69f38d23fd0 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •