vendor:
AShop
by:
Unknown
5.5
CVSS
MEDIUM
Open-Redirection, Cross-Site Scripting
79
CWE
Product Name: AShop
Affected Version From: Prior to AShop 5.1.4
Affected Version To: 5.1.2004
Patch Exists: YES
Related CWE:
CPE: a:ashop:ashop
Platforms Tested:
2011
Multiple Open-Redirection and Cross-Site Scripting Vulnerabilities in AShop
AShop is prone to multiple open-redirection issues and multiple cross-site scripting issues because it fails to sufficiently sanitize user-supplied input. Attackers can exploit these issues to execute arbitrary script or HTML code, steal cookie-based authentication credentials, and conduct phishing attacks. Other attacks may also be possible.
Mitigation:
Upgrade to AShop version 5.1.4 or later.