Description
A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update version to 3.0.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1486 | A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code. |
Github GHSA |
GHSA-p2j7-6g9h-32xh | Cross site scripting in Shopizer |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-16T23:10:36.059Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-23059
No data.
Status : Modified
Published: 2022-03-29T11:15:07.503
Modified: 2024-11-21T06:47:54.347
Link: CVE-2022-23059
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA