Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ian Chong

Researcher fromSEC Consult
#21334of 53,632
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-23489
6.1
2021-12-14
Unknown · Abantecart · CVE-2021-42050
**Name of the Vulnerable Software and Affected Versions** AbanteCart versions prior to 1.3.2 **Description** An issue was discovered that allows DOM Based XSS. **Recommendations** For versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue.
PT-2021-23490
5.4
2021-12-14
Unknown · Abantecart · CVE-2021-42051
**Name of the Vulnerable Software and Affected Versions** AbanteCart versions prior to 1.3.2 **Description** An issue was discovered that allows any low-privileged user with file-upload permissions to upload a malicious SVG document containing an XSS payload. **Recommendations** For versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider restricting file-upload permissions to minimize the risk of exploitation.