Описание
The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.9.0 (исключая)
cpe:2.3:a:s-cart:s-cart:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00173
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
почти 4 года назад
SCart is vulnerable to cross-site scripting (XSS)
EPSS
Процентиль: 39%
0.00173
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79