PT-2024-29025 · Joomla · Hikashop

Published

2024-10-21

·

Updated

2024-10-29

·

CVE-2024-40746

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HikaShop Joomla Component versions prior to 5.1.1
Description A stored cross-site scripting (XSS) issue allows remote attackers to execute arbitrary JavaScript in a user's web browser. This is achieved by including a malicious payload in the description parameter of any product, which is not sanitized in the backend.
Recommendations For versions prior to 5.1.1, update to version 5.1.1 or later to resolve the issue. As a temporary workaround, consider sanitizing the description parameter in the backend to prevent malicious JavaScript execution.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-40746

Affected Products

Hikashop