PT-2026-4513 · Unknown · Peel Shopping
CVE-2021-47897
·
Publicado
2026-01-23
·
Atualizado
2026-01-24
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PEEL Shopping version 9.3.0
Description
The software contains a stored cross-site scripting issue in the
address parameter of the ''change params.php'' script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution. The vulnerable parameter is address.Recommendations
Apply updates to address the issue in the ''change params.php'' script. As a temporary workaround, sanitize user input for the
address parameter to prevent the injection of malicious scripts.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Peel Shopping