PT-2024-5680 · Unknown · Netcat Netshop Cms

Published

2024-07-16

·

Updated

2024-07-16

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netcat Netshop CMS (affected versions not specified)
Description The issue exists due to inadequate protection of the web page structure in the netshop CMS system's netcat module. This allows a remote attacker to execute arbitrary JavaScript code in the user's browser by exploiting the phase parameter vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06393

Affected Products

Netcat Netshop Cms