vendor:
Shopizer
by:
Marek Toth
4.8
CVSS
MEDIUM
Stored XSS and Reflected XSS
79
CWE
Product Name: Shopizer
Affected Version From: <= 2.16.0
Affected Version To: 2.16.0
Patch Exists: YES
Related CWE: CVE-2021-33561, CVE-2021-33562
CPE: 2.3:a:shopizer:shopizer:2.16.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2021
Shopizer 2.16.0 – ‘Multiple’ Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability in Shopizer before version 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration and saved in the database. The code is executed for any user of store administration when information is fetched from backend. A reflected cross-site scripting (XSS) vulnerability in Shopizer before version 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the 'ref' parameter.
Mitigation:
Upgrade to Shopizer version 2.17.0 or later.