What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-shops-cart2 allows DOM-Based XSS.This issue affects e-shops: from n/a through <= 1.0.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-shops-cart2 allows DOM-Based XSS.This issue affects e-shops: from n/a through <= 1.0.4.
Explanation of Vulnerability in Simple Terms
e-shops versions 1.0.4 and earlier contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. The vulnerability requires user interaction—typically clicking a malicious link—and can affect multiple users across the application. An attacker can steal session cookies, redirect users, or deface content visible to other site visitors.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers, stealing cookies or redirecting them to phishing sites.
Potential impact on your site
Visitors can be compromised without your knowledge. Attackers may steal admin session tokens, harvest user data, or spread malware through your site.
Conditions required to exploit
Victim must click an attacker-supplied link or visit a page containing the malicious payload. No authentication required.
Key dates
External resources
Related vulnerabilities