Posts

Showing posts from April, 2025

Script And Tools | Online-Travling-System | Broken Access Control In /admin/viewpackage.php

Image
Hi All,  I am Maloy Roy Orko. Recently in one of my pentest research, I found a Online-Travling-System application By Script And Tools which is an open source Online-Travling-System. It is made with PHP, MYSQL, JAVASCRIPT. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that it did not have any kind of Proper Access Management in  /admin/viewpackage.php  file. This file cam be accessed by anyone even without logging in! It can lead into: Malware Distribution Unauthorized Access  Data Breach Web Shell Installation Reputation Damage The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too.Thats why I am trying to inform everyone about this. Title of the Vulnerability:  Script And Tools | Online-Travling-System | Broken Access Control In /admin/viewpackage.php Vulnerability Class : Broken Acce...

Script And Tools | Online-Travling-System | Broken Access Control In /admin/addpackage.php

Image
Hi All,  I am Maloy Roy Orko. Recently in one of my pentest research, I found a Online-Travling-System application By Script And Tools which is an open source Online-Travling-System. It is made with PHP, MYSQL, JAVASCRIPT. Curious to explore its functionalities downloaded and set it up in my local system.  After fiddling with the source code, I found that it did not have any kind of Proper Access Management in /admin/addpackage.php file. This file cam be accessed by anyone even without logging in! It can lead into: Malware Distribution Unauthorized Access  Data Breach Web Shell Installation Reputation Damage The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too.Thats why I am trying to inform everyone about this. Title of the Vulnerability :  Script And Tools | Online-Travling-System | Broken Access Control In /admin/addpackage.php Vulnerability Class: Broken Access Control...

Script And Tools | Online-Travling-System | Broken Access Control In /admin/addadvertisement.php

Image
Hi All,  I am Maloy Roy Orko. Recently in one of my pentest research, I found a Online-Travling-System application By Script And Tools which is an open source Online-Travling-System. It is made with PHP, MYSQL, JAVASCRIPT. Curious to explore its functionalities downloaded and set it up in my local system.  After fiddling with the source code, I found that it did not have any kind of Proper Access Management in /admin/addadvertisement.php file. This file cam be accessed by anyone even without logging in! It can lead into: Malware Distribution Unauthorized Access  Data Breac Web Shell Installation Reputation Damage The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too.Thats why I am trying to inform everyone about this. Title of the Vulnerability:  Script And Tools | Online-Travling-System | Broken Access Control In /admin/addadvertisement.php Vulnerability Class: Broken Access Co...

Script And Tools | Online-Travling-System | Broken Access Control In /admin/viewenquiry.php

Image
Hi All,  I am Maloy Roy Orko. Recently in one of my pentest research, I found a  Online-Travling-System   application By Script And Tools which is an open source  Online-Travling-System. It is made with PHP, MYSQL, JAVASCRIPT. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that it did not have any kind of Proper Access Management in /admin/viewenquiry.php file.  This file cam be accessed by anyone even without logging in! It can lead into: Malware Distribution Unauthorized Access   Data Breach Web Shell Installation Reputation Damage The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too.Thats why I am trying to inform everyone about this. Title of the Vulnerability:  Script And Tools | Online-Travling-System | Broken Access Control In /admin/viewenquiry.php Vulnerability Cla...

Script and Tools | eCommerce 3.0 | admin/subscriber-csv.php - Information Disclosure

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the /admin/subscriber-csv.php file is vulnerable to Unauthorized access to subscriber data in 'admin/subscriber-csv.php' leading to potential data exposure. It can lead into: - Privacy Violations   - Reputational Damage   - Legal and Regulatory  Consequences   - Increased Risk of Phishing and Spam - Operational Impact   - Loss of Competitive Advantage   The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | admin/subscri...

Script and Tools | eCommerce 3.0 | admin/product-delete.php - CSRF

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the /admin/product-delete.php file is vulnerable to Cross-Site Request Forgery (CSRF)  It can lead into: Unauthorized Actions   Data Manipulation Account Takeover   Financial Loss Compliance Violations   Increased Attack Surface  The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | admin/product-delete.php - CSRF Vulnerability Class : Cross-Site Request Forgery (CSRF) Product Name : eCommerce 3.0  Vendor : https:/github.com/scrip...

Script and Tools | eCommerce 3.0 | admin/order-delete.php - CSRF

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the /admin/order-delete.php file is vulnerable to Cross-Site Request Forgery (CSRF)  It can lead into: Unauthorized Actions    Data Manipulation Account Takeover   Financial Loss Compliance Violations   Increased Attack Surface  The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | admin/order-delete.php - CSRF Vulnerability Class : Cross-Site Request Forgery (CSRF) Product Name : eCommerce 3.0  Vendor : https:/github.com/scriptan...

Script and Tools | eCommerce 3.0 | admin/slider-delete.php - CSRF

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the /admin/slider-delete.php file is vulnerable to Cross-Site Request Forgery (CSRF)  It can lead into: Unauthorized Actions    Data Manipulation Account Takeover   Financial Loss Compliance Violations   Increased Attack Surface  The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability :  Script and Tools | eCommerce 3.0 | admin/slider-delete.php - CSRF Vulnerability Class : Cross-Site Request Forgery (CSRF) Product Name : eCommerce 3.0  Vendor : https:/github.com/scrip...

Script and Tools | eCommerce 3.0 | admin/service-delete.php - CSRF

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the /admin/service-delete.php file is vulnerable to Cross-Site Request Forgery (CSRF)  It can lead into: Unauthorized Actions Data Manipulation Account Takeover   Financial Loss Compliance Violations   Increased Attack Surface  The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | admin/service-delete.php - CSRF Vulnerability Class : Cross-Site Request Forgery (CSRF) Product Name : eCommerce 3.0  Vendor : https:/github.com/scriptandtools/ V...

Script and Tools | eCommerce 3.0 | admin/faq-delete.php - CSRF

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the /admin/faq-delete.php file is vulnerable to Cross-Site Request Forgery (CSRF)  It can lead into: Unauthorized Actions    Data Manipulation Account Takeover   Financial Loss Compliance Violations   Increased Attack Surface  The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | admin/faq-delete.php - CSRF Vulnerability Class: Cross-Site Request Forgery (CSRF) Product Name: eCommerce 3.0  Vendor: https:/github.com/scriptandtools/...

Script and Tools | eCommerce 3.0 | admin/subscriber-delete.php - CSRF

Image
Hi All,  I am Maloy Roy Orko Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the / admin/subscriber-delete.php file is vulnerable to Cross-Site Request Forgery (CSRF)  It can lead into: Unauthorized Actions    Data Manipulation Account Takeover   Financial Loss Compliance Violations   Increased Attack Surface  The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | admin/customer-delete.php - CSRF Vulnerability Class : Cross-Site Request Forgery (CSRF) Product Name : eCommerce 3.0  Vendor : https://githu...

Script and Tools | eCommerce 3.0 | admin/customer-delete.php - CSRF

Image
Hi All,  I am Maloy Roy Orko CVE Number : CVE-2025-3557 Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the admin/customer-delete.php file is vulnerable to  Cross-Site Request Forgery (CSRF)   It can lead into: Unauthorized Action s     Data Manipulation Account Takeover   Financial Loss Compliance Violations   Increased Attack Surface  The Main Thing Is, If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability :  Script and Tools | eCommerce 3.0 | admin/customer-delete.php - Cross-Site Request Forgery (CSRF) Vulnerability Class : Cross-Site Request Forgery (...

Script and Tools | eCommerce 3.0 | admin/login.php - No Limit To Authentication Attempts To Admin Login

Image
Hi All,  I am Maloy Roy Orko CVE Number : CVE-2025-3556 Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the admin/login.php file is vulnerable to CWE-307: Improper Restriction of Excessive Authentication Attempts. It can lead into: - Unauthorized Data Access - Account Takeover - Privilege Escalation - Denial of Service (DoS) - Reputation Damage - Regulatory Consequences The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | admin/login.php - No Limit To Authentication Attempts To Admin Login Vulnerability Class: CWE-307 : Improper Restriction of Ex...

Script and Tools | eCommerce 3.0 | login.php - No Limit To Authentication Attempts To User Login

Image
Hi All,  I am Maloy Roy Orko CVE Number : CVE-2025-3555 Recently in one of my pentest research, I found a E-commerce System By Script And Tools which is an open source E-commerce Software. Curious to explore its functionalities, I downloaded and set it up in my local system.  After fiddling with the source code, I found that the admin/login.php file is vulnerable to CWE-307: Improper Restriction of Excessive Authentication Attempts  It can lead into: - Unauthorized Data Access - Account Takeover - Privilege Escalation - Denial of Service (DoS) - Reputation Damage - Regulatory Consequences The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this. Title of the Vulnerability:  Script and Tools | eCommerce 3.0 | login.php - Excessive Authentication Attempts  Vulnerability Class: CWE-307: Improper Restriction of Excessive Auth...