PT-2022-18427 · Unknown · Ecommerce-Website

Published

2022-04-04

·

Updated

2022-04-27

·

CVE-2022-27436

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ecommerce-Website version 1.1.0
Description A cross-site scripting (XSS) issue exists in the /public/admin/index.php?add user endpoint, allowing attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
Recommendations For Ecommerce-Website version 1.1.0, consider disabling the /public/admin/index.php?add user endpoint until a patch is available to prevent exploitation. Restrict access to this endpoint to minimize the risk of arbitrary web script or HTML execution. Avoid using the username field in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27436

Affected Products

Ecommerce-Website