Description
In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/shopizer-ecommerce/shopizer/commit/929ca0839a80c6f4dad087e0259089908787ad2a
Third Party Advisory x_refsource_confirm
https://github.com/shopizer-ecommerce/shopizer/security/advisories/GHSA-8pc4-gvfw-634p
Scores
CVSS v3
9.1
EPSS
0.0027
EPSS Percentile
50.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Details
CWE
CWE-79
Status
published
Products (1)
shopizer/shopizer
< 2.11.0
Published
May 08, 2020
Tracked Since
Feb 18, 2026