vendor:
VirtueMart
by:
Mattia Furlani
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: VirtueMart
Affected Version From: 3.1.14
Affected Version To: 3.2.14
Patch Exists: YES
Related CWE: CVE-2018-7465
CPE: virtuemart
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
VirtueMart 3.1.14 – Persistent Cross-Site Scripting
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the admin area of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything after the </textarea>, leading to a possible XSS.
Mitigation:
Upgrade to 3.2.14