PT-2024-29025 · Joomla · Hikashop
Published
2024-10-21
·
Updated
2024-10-29
·
CVE-2024-40746
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HikaShop Joomla Component versions prior to 5.1.1
Description
A stored cross-site scripting (XSS) issue allows remote attackers to execute arbitrary JavaScript in a user's web browser. This is achieved by including a malicious payload in the
description parameter of any product, which is not sanitized in the backend.Recommendations
For versions prior to 5.1.1, update to version 5.1.1 or later to resolve the issue.
As a temporary workaround, consider sanitizing the
description parameter in the backend to prevent malicious JavaScript execution.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hikashop