Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 Maven

Cross site scripting in Shopizer

GHSA-p2j7-6g9h-32xh · CVE-2022-23059

Published · Modified

Description

A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions v2.0.2 through v2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.

Ready to move

Start Securing

Free, no credit card | First findings in minutes