PT-2019-18966 · Unknown · Online Store

Larry W. Cashdollar

·

Published

2019-10-01

·

Updated

2019-10-04

·

CVE-2019-8289

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Online Store version 1.0
Description The issue concerns a stored XSS in the admin/user view.php file, specifically affecting the adidas member email variable.
Recommendations For Online Store version 1.0, consider restricting access to the admin/user view.php file until a patch is available, and avoid using the adidas member email variable in this context to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-8289

Affected Products

Online Store