Projectworlds · Online-Shopping-Webvsite-In-Php · CVE-2021-46024
**Name of the Vulnerable Software and Affected Versions**
Projectworlds online-shopping-webvsite-in-php version 1.0
**Description**
The issue is related to a SQL Injection vulnerability. This vulnerability can be exploited via the `id` parameter in the cart add.php file. No login is required to exploit this issue.
**Recommendations**
For Projectworlds online-shopping-webvsite-in-php version 1.0, consider restricting access to the `id` parameter in the cart add.php file until a patch is available. As a temporary workaround, avoid using the `id` parameter in the affected cart add.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.