PT-2021-19674 · Cs Cart · Cs-Cart

L00Neyhacker

·

Published

2021-09-14

·

Updated

2021-09-22

·

CVE-2021-32202

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: CS-Cart version 4.11.1
Description: The issue allows for copy-paste XSS by manipulating the post description field in the blog post creation page.
Recommendations: For CS-Cart version 4.11.1, consider restricting access to the blog post creation page until a fix is available, and avoid manipulating the post description field to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32202

Affected Products

Cs-Cart