CVE-2021-47897
HIGHPEEL Shopping 9.3.0 - Stored Cross-Site Scripting via Address Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47897. PoCs published by Anmol K Sachan.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in PEEL Shopping 9.3.0 via the 'address' parameter in the change_params.php script. The payload bypasses basic filters using obfuscation techniques to trigger JavaScript execution upon user interaction.
Description
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in PEEL Shopping 9.3.0 via the 'address' parameter in the change_params.php script. The payload bypasses basic filters using obfuscation techniques to trigger JavaScript execution upon user interaction.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N