PT-2021-19674 · Cs Cart · Cs-Cart
L00Neyhacker
·
Published
2021-09-14
·
Updated
2021-09-22
·
CVE-2021-32202
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
CS-Cart version 4.11.1
Description:
The issue allows for copy-paste XSS by manipulating the
post description field in the blog post creation page.Recommendations:
For CS-Cart version 4.11.1, consider restricting access to the blog post creation page until a fix is available, and avoid manipulating the
post description field to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cs-Cart