PT-2022-27715 · Shoplazza · Shoplazza Lifestyle
Published
2022-12-18
·
Updated
2022-12-22
·
CVE-2022-4600
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Shoplazza LifeStyle version 1.1
Description
A vulnerability was found in the Product Carousel Handler component, affecting an unknown part of the file
/admin/api/theme-edit/. The manipulation of the Heading/Description argument leads to cross-site scripting. It is possible to initiate the attack remotely.Recommendations
For Shoplazza LifeStyle version 1.1, consider disabling the
Heading/Description argument in the /admin/api/theme-edit/ endpoint until a patch is available. Restrict access to the Product Carousel Handler component to minimize the risk of exploitation.Fix
Improper Neutralization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shoplazza Lifestyle