### [CVE-2024-13203](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-13203) ![](https://img.shields.io/static/v1?label=Product&message=E-Commerce-PHP&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%201.0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross-Site%20Request%20Forgery&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Missing%20Authorization&color=brighgreen) ### Description A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. ### POC #### Reference - https://www.websecurityinsights.my.id/2024/12/ecommerce-php-by-kurniaramadhan-sql.html?m=1 #### Github No PoCs found on GitHub currently.