PT-2025-47011 · Codecanyon · Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution
4M3Rr0R
·
Publicado
2025-11-14
·
Atualizado
2025-11-21
·
CVE-2025-13186
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution versions prior to 4.1
Description
A flaw exists in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution. Manipulation of the
Search argument in an unknown function within the file '/dashboard/Ccustomer/manage customer' can lead to cross site scripting. This attack can be initiated remotely. The details of the exploit have been publicly released. The vendor was notified but did not respond.Recommendations
Update Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution to version 4.1 or later.
As a temporary workaround, sanitize the
Search parameter before processing it in the affected function within the '/dashboard/Ccustomer/manage customer' file.Exploit
Correção
Code Injection
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution