vendor:
Electricks eCommerce
by:
Nawaf Alkeraithe
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Electricks eCommerce
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:electricks:electricks_ecommerce
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
Electricks eCommerce 1.0 – Cross-Site Scripting
When a user signs up for an account on the following url: Electricks-shop/pages/user_signup.php, the contact info input field isn't validated before displaying it to the admin control panel page where the script will be executed. For testing, an admin can register at /Electricks-shop/pages/admin_signup.php by sending a POST request with a malicious script in the contact field.
Mitigation:
Input validation should be implemented to prevent malicious scripts from being executed.