PT-2026-4513 · Unknown · Peel Shopping

Published

2026-01-23

·

Updated

2026-01-24

·

CVE-2021-47897

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PEEL Shopping version 9.3.0
Description The software contains a stored cross-site scripting issue in the address parameter of the ''change params.php'' script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution. The vulnerable parameter is address.
Recommendations Apply updates to address the issue in the ''change params.php'' script. As a temporary workaround, sanitize user input for the address parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47897

Affected Products

Peel Shopping