vendor:
Bagisto
by:
Mohamed Abdellatif Jaber
8.8
CVSS
HIGH
Client-Side Template Injection
94
CWE
Product Name: Bagisto
Affected Version From: 1.3.2003
Affected Version To: 1.3.2003
Patch Exists: Yes
Related CWE:
CPE: bagisto
Platforms Tested: Windows, Chrome, Firefox
2021
Bagisto 1.3.3 – Client-Side Template Injection
A client-side template injection vulnerability in Bagisto 1.3.3 allows an attacker to inject arbitrary JavaScript code into the application. An attacker can exploit this vulnerability by registering an account and editing their profile name and address with a malicious payload. When an administrator or any other user views the profile or order, the malicious code will be executed.
Mitigation:
Upgrade to the latest version of Bagisto