PT-2025-47011 · Codecanyon · Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution

4M3Rr0R

·

Published

2025-11-14

·

Updated

2025-11-21

·

CVE-2025-13186

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution versions prior to 4.1
Description A flaw exists in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution. Manipulation of the Search argument in an unknown function within the file '/dashboard/Ccustomer/manage customer' can lead to cross site scripting. This attack can be initiated remotely. The details of the exploit have been publicly released. The vendor was notified but did not respond.
Recommendations Update Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution to version 4.1 or later. As a temporary workaround, sanitize the Search parameter before processing it in the affected function within the '/dashboard/Ccustomer/manage customer' file.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-13186

Affected Products

Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution