Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38609 | A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend. |
| Link | Providers |
|---|---|
| https://www.hikashop.com/ |
|
Tue, 29 Oct 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hikashop
Hikashop hikashop |
|
| CPEs | cpe:2.3:a:hikashop:hikashop:*:*:*:*:*:joomla\!:*:* | |
| Vendors & Products |
Hikashop
Hikashop hikashop |
|
| Metrics |
cvssV3_1
|
Mon, 21 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Oct 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend. | |
| Title | Extension - hikashop.com - Stored cross site scripting vulnerability in Hikashop component for Joomla < 5.1.1 | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2025-03-20T04:35:06.479Z
Reserved: 2024-07-09T16:16:21.865Z
Link: CVE-2024-40746
Updated: 2024-10-21T16:45:53.056Z
Status : Modified
Published: 2024-10-21T17:15:03.330
Modified: 2025-03-19T16:15:26.030
Link: CVE-2024-40746
No data.
OpenCVE Enrichment
No data.
EUVD