PT-2022-12714 · Unknown · H.H.G Multistore
Published
2022-01-28
·
Updated
2022-02-02
·
CVE-2021-46447
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
H.H.G Multistore versions 5.1.0 and below
Description
A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the
State parameter under the Address Book module.Recommendations
For versions 5.1.0 and below, consider disabling the Address Book module until a patch is available. Restrict access to the
State parameter to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
H.H.G Multistore