PT-2025-47011 · Codecanyon · Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution
4M3Rr0R
·
Published
2025-11-14
·
Updated
2025-11-21
·
CVE-2025-13186
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution versions prior to 4.1
Description
A flaw exists in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution. Manipulation of the
Search argument in an unknown function within the file '/dashboard/Ccustomer/manage customer' can lead to cross site scripting. This attack can be initiated remotely. The details of the exploit have been publicly released. The vendor was notified but did not respond.Recommendations
Update Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution to version 4.1 or later.
As a temporary workaround, sanitize the
Search parameter before processing it in the affected function within the '/dashboard/Ccustomer/manage customer' file.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bdtask/Codecanyon Isshue Multi Store Ecommerce Shopping Cart Solution