An XSS issue was discovered in Sandoba CP:Shop v2016.1. The vulnerability is located in the `admin.php` file of the `./cpshop/` module. Remote attackers are able to inject their own script codes to the client-side requested vulnerable web-application parameters. The attack vector of the vulnerability is non-persistent and the request method to inject/execute is GET with the path, search, rename, or dir parameter.
References
Link | Resource |
---|---|
https://www.vulnerability-lab.com/get_content.php?id=2122 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-06-29 14:29
Updated : 2024-02-28 16:25
NVD link : CVE-2018-13001
Mitre link : CVE-2018-13001
CVE.ORG link : CVE-2018-13001
JSON object : View
Products Affected
sandoba
- cp\
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')