Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46v4-5mc8-q2cf

Опубликовано: 23 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.3

Описание

GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability

A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions.

Пакеты

Наименование

s-cart/core

composer
Затронутые версииВерсия исправления

<= 9.0.5

Отсутствует

Наименование

gp247/core

composer
Затронутые версииВерсия исправления

< 1.1.24

1.1.24

EPSS

Процентиль: 20%
0.00066
Низкий

1.3 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
5 месяцев назад

A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a crafted User-Agent header. The script is executed in an administrator's browser when they view the security log page, which could lead to session hijacking or other malicious actions.

EPSS

Процентиль: 20%
0.00066
Низкий

1.3 Low

CVSS4

Дефекты

CWE-79