Логотип exploitDog
bind:CVE-2022-21149
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21149

Количество 2

Количество 2

nvd логотип

CVE-2022-21149

почти 4 года назад

The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7pfc-cx3m-v22x

почти 4 года назад

SCart is vulnerable to cross-site scripting (XSS)

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-21149

The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) which can lead to cookie stealing of any victim that visits the affected URL so the attacker can gain unauthorized access to that user's account through the stolen cookie.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-7pfc-cx3m-v22x

SCart is vulnerable to cross-site scripting (XSS)

CVSS3: 5.4
0%
Низкий
почти 4 года назад

Уязвимостей на страницу