vendor:
Active Super Shop CMS v2.5 (CMS) (Web-Application)
by:
Vulnerability Laboratory
5.4
CVSS
MEDIUM
HTML Injection
CWE
Product Name: Active Super Shop CMS v2.5 (CMS) (Web-Application)
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2023
Active Super Shop CMS v2.5 – HTML Injection Vulnerabilities
Multiple html injection vulnerabilities have been discovered in the Active Super Shop Multi-vendor CMS v2.5 web-application. The web vulnerability allows remote attackers to inject their own html codes with a persistent vector to manipulate application content. The persistent html injection web vulnerabilities are located in the name, phone, and address parameters of the manage profile and products.