PT-2025-48396 · Unknown · Winston-Dsouza Ecommerce-Website

Dream123

·

Published

2025-11-30

·

Updated

2025-11-30

·

CVE-2025-13793

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions winston-dsouza Ecommerce-Website versions up to 87734c043269baac0b4cfe9664784462138b1b2e
Description A weakness exists in winston-dsouza Ecommerce-Website. The issue affects some unknown functionality within the /includes/header menu.php file, specifically the GET Parameter Handler component. Manipulation of the Error parameter can lead to cross site scripting. The attack can be executed remotely. The exploit has been made publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13793

Affected Products

Winston-Dsouza Ecommerce-Website