Vulnerabilities
Vulnerable Software
Newbee-Mall Project:  >> Newbee-Mall  Security Vulnerabilities
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
CVSS Score
6.1
EPSS Score
0.002
Published
2021-01-26
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-01-26
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
CVSS Score
7.5
EPSS Score
0.002
Published
2021-01-26
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
CVSS Score
9.8
EPSS Score
0.006
Published
2019-11-18


Contact Us

Shodan ® - All rights reserved