Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-3329 | A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affects an unknown part of the component Restaurant Order Handler. The manipulation of the argument Login/Password leads to cleartext transmission of sensitive information. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 2.3 | <1% | PoC |
| — | |
| CVE-2018-20626 +1 in the same advisory: …20627 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. NVD description · AI analysis pending | 6.5 group max | 2% | PoC |
| — | |
| CVE-2017-17605 | Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — |