The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-PHP-SCARTCORE-2389036 | Third Party Advisory |
https://snyk.io/vuln/SNYK-PHP-SCARTSCART-2389035 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-05-01 16:15
Updated : 2024-02-28 19:09
NVD link : CVE-2022-21149
Mitre link : CVE-2022-21149
CVE.ORG link : CVE-2022-21149
JSON object : View
Products Affected
s-cart
- s-cart
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')