
SourceCodester Online Eyewear Shop リモートファイルインクルード脆弱性
ベンダー: Sourcecodester [https://www.sourcecodester.com/php/16089/online-eyewear-shop-website-using-php-and-mysql-free-download.html]
参照: https://github.com/gurudattch/
製品: Online Eyewear Shop バージョン: 1.0
脆弱性の概要:
Sourcecodester が開発した Online Eyewear Shop バージョン 1.0 には、カートID・ID 操作の脆弱性があります。この脆弱性により、攻撃者はカートIDを変更することで、他のユーザーのカートに不要な商品を追加したり削除したりすることができます。


同様に、この機能は商品の削除に関しても脆弱です。

