PT-2025-43200 · Xtemos · Woodmart
Published
2025-10-22
·
Updated
2025-11-18
·
CVE-2025-49936
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
xtemos WoodMart versions prior to 8.3.2
Description
The software contains a flaw related to improper input handling during web page generation, specifically a DOM-Based Cross-site Scripting issue. This allows for the execution of malicious scripts within the user's browser. The vulnerability exists due to insufficient sanitization of input data, potentially enabling attackers to inject arbitrary code into web pages.
Recommendations
Update xtemos WoodMart to version 8.3.2 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woodmart