CVE-2021-33561
MEDIUMShopizer < 2.17.0 - Stored Cross-Site Scripting via Customer Name Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-33561. PoCs published by Marek Toth.
AI-analyzed exploit summary This exploit demonstrates stored and reflected XSS vulnerabilities in Shopizer versions <= 2.16.0. The stored XSS is triggered via the 'customer_name' field in the administration panel, while the reflected XSS is executed through the 'ref' parameter in product URLs.
Description
A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.
Exploits (1)
This exploit demonstrates stored and reflected XSS vulnerabilities in Shopizer versions <= 2.16.0. The stored XSS is triggered via the 'customer_name' field in the administration panel, while the reflected XSS is executed through the 'ref' parameter in product URLs.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N