vendor:
VirtueMart Shopping-Cart
by:
CraCkEr
5.5
CVSS
MEDIUM
Reflected XSS
79
CWE
Product Name: VirtueMart Shopping-Cart
Affected Version From: 4.0.12
Affected Version To: 4.0.12
Patch Exists: NO
Related CWE:
CPE: a:virtuemart_team:virtuemart:4.0.12
Platforms Tested: Windows 10 Pro
2023
Joomla VirtueMart Shopping-Cart 4.0.12 – Reflected XSS
The attacker can send a malicious URL containing an XSS payload to the victim, potentially allowing them to perform actions such as stealing session tokens or login credentials.
Mitigation:
Apply proper input validation and sanitization techniques to prevent the execution of malicious scripts.