CVE-2014-4963
Shopizer <1.1.5 - XSS
Title source: llmDescription
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.
Exploits (1)
Scores
EPSS
0.0360
EPSS Percentile
87.8%
Details
Status
published
Products (1)
shopizer/shopizer
< 1.1.5
Published
Jul 15, 2014
Tracked Since
Feb 18, 2026