Virtuemart · Virtuemart · CVE-2018-7465
**Name of the Vulnerable Software and Affected Versions**
VirtueMart versions prior to 3.2.14
**Description**
A cross-site scripting (XSS) issue was found. The textareas in the backend of the plugin are vulnerable to this issue. By adding `</textarea>` to the value and saving the product/config, an attacker can execute arbitrary code when the product/config is edited again, potentially leading to XSS attacks.
**Recommendations**
For versions prior to 3.2.14, update to version 3.2.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the backend of the plugin to minimize the risk of exploitation. Avoid using the textareas in the backend until the issue is resolved.