In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://projectworlds.in/free-projects/php-projects/free-download-online-shopping-system/ | product |
https://github.com/projectworldsofficial/online-shopping-webvsite-in-php/issues/2 | issue tracking exploit third party advisory |