PT-2025-47011 · Codecanyon · Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution

4M3Rr0R

·

Publicado

2025-11-14

·

Atualizado

2025-11-21

·

CVE-2025-13186

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution versions prior to 4.1
Description A flaw exists in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution. Manipulation of the Search argument in an unknown function within the file '/dashboard/Ccustomer/manage customer' can lead to cross site scripting. This attack can be initiated remotely. The details of the exploit have been publicly released. The vendor was notified but did not respond.
Recommendations Update Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution to version 4.1 or later. As a temporary workaround, sanitize the Search parameter before processing it in the affected function within the '/dashboard/Ccustomer/manage customer' file.

Exploit

Correção

Code Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13186

Produtos afetados

Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution