Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.8 Maven

Cross-site scripting in Shopizer

GHSA-rcp4-jm2v-mr3f · CVE-2021-33561

Published · Modified

Description

A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.

Ready to move

Start Securing

Free, no credit card | First findings in minutes