Record summary

CVE-2021-33562 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

A reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the ref parameter to a page about an arbitrary product, e.g., a product/insert-product-name-here.html/ref= URL.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.17.0 · Fixed in 2.17.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBShopizer 2.16.0 - 'Multiple' Cross-Site Scripting (XSS)ExploitDB exploitby Marek TothNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

4