Ordermanagementscript maintains a narrow portfolio of web-based service-delivery applications such as professional-service and online-tutoring scripts, serving small-to-medium business and niche hosting environments. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through application-layer input-handling weaknesses—cross-site request forgery, path traversal, cross-site scripting, and SQL injection—alongside information-exposure flaws that are endemic to web applications lacking defense-in-depth input validation and output encoding. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ordermanagementscript over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17928CRITICAL PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter. | Dec 27, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-17930HIGH PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel. | Dec 27, 2017 | 8.8 | 26 | NO | NO |
CVE-2018-6934HIGH CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3. | Apr 12, 2018 | 8.8 | 24 | NO | NO |
CVE-2017-17927MEDIUM PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/. | Dec 27, 2017 | 5.3 | 19 | NO | NO |
CVE-2017-17924MEDIUM PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php. | Dec 27, 2017 | 5.3 | 19 | NO | NO |
CVE-2017-17929MEDIUM PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter. | Dec 27, 2017 | 4.8 | 18 | NO | NO |
CVE-2017-17926MEDIUM PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. | Dec 27, 2017 | 5.3 | 18 | NO | NO |
CVE-2017-17925MEDIUM PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter. | Dec 27, 2017 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ordermanagementscript.
Media articles that mention a CVE ID that affects a product developed by Ordermanagementscript — matched by CVE ID, not by vendor name.