PT-2026-30597 · Code Projects · Online Shop Store

Jacky_159

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5647

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions code-projects Online Shoe Store version 1.0
Description A cross-site scripting issue exists in the Add Product Page component of code-projects Online Shoe Store version 1.0. The issue is located in an unknown part of the /admin/admin feature.php file. Manipulation of the product name argument can trigger the vulnerability. The attack can be launched remotely. The exploit is publicly available.
Recommendations For code-projects Online Shoe Store version 1.0, sanitize the product name argument to prevent cross-site scripting.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-5647

Affected Products

Online Shop Store