PT-2026-4513 · Unknown · Peel Shopping

CVE-2021-47897

·

Published

2026-01-23

·

Updated

2026-01-24

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PEEL Shopping version 9.3.0
Description The software contains a stored cross-site scripting issue in the address parameter of the ''change params.php'' script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution. The vulnerable parameter is address.
Recommendations Apply updates to address the issue in the ''change params.php'' script. As a temporary workaround, sanitize user input for the address parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47897

Affected Products

Peel Shopping