CVE-2021-33561

MEDIUM

Shopizer <2.17.0 - XSS

Title source: llm

Description

A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.

Exploits (1)

exploitdb WORKING POC
by Marek Toth · textwebappsjava
https://www.exploit-db.com/exploits/49901

Scores

CVSS v3 4.8
EPSS 0.0073
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
com.shopizer/shopizer 0 - 2.17.0Maven
shopizer/shopizer < 2.17.0
Published May 24, 2021
Tracked Since Feb 18, 2026