What the vulnerability does
01Description
Auth. (Shop Manager+) Stored Cross-Site Scripting (XSS) vulnerability in CedCommerce Recently viewed and most viewed products plugin <= 1.1.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (Shop Manager+) Stored Cross-Site Scripting (XSS) vulnerability in CedCommerce Recently viewed and most viewed products plugin <= 1.1.1 versions.
Explanation of Vulnerability in Simple Terms
A stored cross-site scripting (XSS) vulnerability exists in CedCommerce's Recently Viewed and Most Viewed Products extension. An authenticated admin user can inject malicious JavaScript that executes in the browsers of other site visitors. The vulnerability requires admin privileges and user interaction to exploit, but can affect multiple users across the site.
What an attacker can do
Inject malicious JavaScript that runs in visitors' browsers and steals data or performs actions on their behalf.
Potential impact on your site
Visitors' browsers could be compromised if an admin account is breached or a malicious admin is added to the site.
Conditions required to exploit
Attacker must have admin-level access and trick a user into visiting a crafted page or clicking a link.
Key dates
External resources
Related vulnerabilities