PT-2026-5552 · Unknown · Easy Cart Shopping Cart 2021
Published
2026-02-01
·
Updated
2026-02-01
·
CVE-2021-47856
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Cart Shopping Cart version 2021
Description
The software contains a non-persistent cross-site scripting issue in the search module. An attacker can inject malicious script code through the search input, specifically the
keyword parameter, potentially compromising user sessions and manipulating application content. The affected API endpoint is the search functionality. The vulnerable parameter is keyword.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Cart Shopping Cart 2021