Browse all 4 CVE security advisories affecting fanzila. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Fanzila operates as an e-commerce platform enabling online transactions and digital marketplaces. Historically, vulnerabilities in Fanzila have commonly included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from improper input validation and access control weaknesses. The platform has experienced security incidents where attackers exploited these vulnerabilities to compromise user accounts, execute arbitrary code, and gain unauthorized administrative access. These issues have primarily affected the platform's web interface and API endpoints, highlighting ongoing challenges in secure coding practices and input sanitization. Fanzila's security posture reflects typical risks faced by e-commerce systems handling sensitive financial and personal data.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2013-10017 | fanzila WebFinance save_roles.php sql injection — WebFinanceCWE-89 | 5.5 | Medium | 2023-02-03 |
| CVE-2013-10018 | fanzila WebFinance save_contact.php sql injection — WebFinanceCWE-89 | 5.5 | Medium | 2023-02-03 |
| CVE-2013-10016 | fanzila WebFinance save_taxes.php sql injection — WebFinanceCWE-89 | 5.5 | Medium | 2023-02-03 |
| CVE-2013-10015 | fanzila WebFinance save_Contract_Signer_Role.php sql injection — WebFinanceCWE-89 | 5.5 | Medium | 2023-02-03 |
This page lists every published CVE security advisory associated with fanzila. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.